Splunk Search

EventViewer No Display

halbeisendv
Path Finder

User has the "admin" RBAC role
User uses dark theme
User uses several workstations with Chrome and IE

A simple search such as index=_internal, but not limited to this index. The search executes and the user is able to see, i.e. the search produces records) the fields side bar and the timeline. However, there is no visual information in the Events Viewer. This scenario is intermittent.

This user is the only user who experiences this problem. Stumped?

0 Karma

halbeisendv
Path Finder

Not something I considered, but no, this is not the resolution.

0 Karma

nickhills
Ultra Champion

Is it possible that the user has hidden the timeline vis?
alt text

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...