Dashboards & Visualizations

Why are users not able to see graphs in Dashboard after creating a field extraction?

NeerajDhapola7
Path Finder

Step 1: fields were extracted using separator (,) with Splunk's delimiter and fields name were like starttime,errordate,instance,proxy,filename .....etc

Due to some issue, separator was updated from comma , to pipe |.

Step2 : Deleted previous field extraction and created new field extraction using separator(|) with same name of fields.

Step 3: Permission is updated from private to APP wth READ only to everyone.

Step 4 : Again going back to existing dashboard i am able to view all graph with latest data.

Issue : other User not able to view existing dashboard graphs.
in some post it was suggested to update permission for field transformation, but i am not getting any field transformation which is created by me.

Please let me know if any more clarification required.

Thanks
Neeraj Singh Dhapola

0 Karma

woodcock
Esteemed Legend

You need to have your admin restart splunk in the next maintenance window.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Are you using the same sourcetype for the new field you made?

0 Karma

NeerajDhapola7
Path Finder

yes same sourcetype or index
As I can see the results that means query is working.
Issue is only with VIEW (Permission) for other users which I have given already in field extration

0 Karma

woodcock
Esteemed Legend

Did you restart splunk on the search head or do a debug/refresh?

0 Karma

NeerajDhapola7
Path Finder

I am normal power user don't have admin rights or cant restart the search head.
Please let me know how can I do debug and refresh.

Appreciates for the response.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

http://splunkURL:port/debug/refresh

Hit the refresh button and it will give you a list of all the configs that were refreshed (Some things will require a Splunkd restart)

0 Karma

NeerajDhapola7
Path Finder

yes i tried same after getting your post but i am getting below response i think admin only can do

response>
messages>
msg type="ERROR">Forbidden
/messages>

/response>

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...