Did you get this resolved? I'm having the exact same issue. - a ref="<reportname>" works fine with the restricted read permissions (no access to index data) but I cannot pass tokens to the report - a <query>| savedsearch <reportname> tokens=$tokens$ works fine for results but cannot run as report owner How does one run as the report owner and still pass in tokens?
... View more
Hi Guiseppe. I have not been sucessfull yet, but I'm still working on the principal and have asked another question on how the reference the _meta variable in a transform. Kind regards Lars
... View more
Thank you. I clicked the vote. 🙂
Do you know how to place the report last run date/time on the dashboard? Since the data is essentially static, and only as good as the last run. I would like to place the last run date so it's "Effective as of..."
... View more
earlier i dropped mail to certification, later to education_APAC and now i forwarded the same to elearn. lets see. thanks for your support.
... View more
Thanks, Below command fix that issue.
chmod 400 /opt/splunk/var/lib/splunk/kvstore/mongo/splunk.key
I was not able to open Splunk Add on builder TA due to this issue. Now its been fixed by changing the permission to the mongo key file.
... View more