Reporting

splunk user can schedule reports but not dashboard

loganramirez
Path Finder

Hi.

Running 9.0.6 and a user (who is the owner)  can schedule REPORTS, but not DASHBOARDS.

It's a CLASSIC dashboard (not the new fancy one Stooooodio one).

Dashboards --> Find Dashboard --> Edit button --> NO 'Edit Schedule'
Open dashboard, top right export, NO 'Schedule PDF'

My local admin says 'maybe they changed something in 9.0.6), but I'm unconvinced until this legendary community agrees.

"feels" like a permission missing is all.

 

 

Labels (1)
0 Karma
1 Solution

kiran_panchavat
Contributor

@loganramirez 

To schedule PDF email to mail server that does not require SMTP authentication, you must have the list_settings capability and use the sendemail command. If you want users who do not have the admin, splunk-system-role, or can_delete roles to be able to send email notifications from their searches, you must grant them the list_settings capability. By default, only the admin, splunk-system-role, and can_delete roles have access to list_settings.

 

kiran_panchavat_0-1724920246509.png

 

View solution in original post

kiran_panchavat
Contributor

@loganramirez 

To schedule PDF email to mail server that does not require SMTP authentication, you must have the list_settings capability and use the sendemail command. If you want users who do not have the admin, splunk-system-role, or can_delete roles to be able to send email notifications from their searches, you must grant them the list_settings capability. By default, only the admin, splunk-system-role, and can_delete roles have access to list_settings.

 

kiran_panchavat_0-1724920246509.png

 

tej57
Contributor

Hello @loganramirez,

Can you confirm if the user trying to schedule a PDF is having the list_settings capability enabled on the role? As mentioned in the following doc, list_settings capability is required to have the menu option populated.

Doc - https://docs.splunk.com/Documentation/Splunk/9.3.0/Viz/DashboardPDFs#Schedule_PDF_delivery 

 

Thanks,
Tejas.

 

---

If the above solution works, an upvote is appreciated !!

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...