Dashboards & Visualizations

Preview in dashboard works only for some users ?

alexantao
Path Finder

In splunk 6.0, I created two Saved Searches.

I have an user with admin access and another user with user access (I don't know if it really matters in this case).

I created a dashboard with 4 panels, the last 2 are Pivot graphics. The first two panels are reports based on these 2 saved searches I created.

The problem is that when I open the dashboard with the user with "user" level access, one of then is shown as the search is being executed, but the other does not, only the Loadng 0% and the panel is shown. No errors are presented. If I open the same dashboard with the user with admin access, both panels are shown as the search is being executed.

Inspecting the job, BOTH has the isPreviewEnabled=False, and cannot find anywhere to enable it.

I've created a third search to test, similar to the one that has a problem, and nothing changed.

My searches are configured as:

    Search-Problem    2013-10-12 00:00:00 BRT  flashtimeline user Clients 0 Global
    Search-probl-new  None                     None      user Clients 0 Global
    Search-OK     2013-10-12 00:00:00 BRT  None      user Clients 0 Global

Please, How can I make all reports preview the results as the seach is being executed ?

Thanks a lot !

Tags (3)
0 Karma

ziegfried
Influencer

My suspicion is that the limit on current searches for the user role (3 by default) causes the job driving one of the panels to be queued. It's not possible to preview a job as long as it's queued.

You could try to increase the limit in Settings -> Access Controls -> Roles.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...