Users with an Admin or Power role are able to view the Seclytics dashboard provided by the "Seclytics for Splunk App". However, when users with the "User" role attempt to access the same dashboard, the content does not display.
Additionally, we discovered that the lookup file "event_by_days.csv" is missing from the expected directory:
/opt/splunk/etc/apps/seclytics-splunk-app/lookups/.
We would like to understand the following:
Hi @dipali
Im unable to download the app to check, but it sounds like there could be knowledge objects within the app which are not readable by the User role due to their RBAC/Metadata configuration.
Please check within the metadata/default.meta (and local.meta if you have made changes) to see what the different permissions are - feel free to share the contents here so we can walk through it.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing