Users with an Admin or Power role are able to view the Seclytics dashboard provided by the "Seclytics for Splunk App". However, when users with the "User" role attempt to access the same dashboard, the content does not display. Additionally, we discovered that the lookup file "event_by_days.csv" is missing from the expected directory: /opt/splunk/etc/apps/seclytics-splunk-app/lookups/. We would like to understand the following: Why is the dashboard visible to Admin/Power roles but not to the User role? Are there specific role-based permissions required to access this dashboard? Or is there a configuration change needed on our end to ensure all roles can access the content correctly? Seclytics for Splunk App
... View more