All Apps and Add-ons

Dashbord shows different results to different users

discoverneeraj
Explorer

Hello All,
I executed the following search and saved it as a dashboard:

index="tcpr-dispatcher" host="orl_displogs" sourcetype=DispatcherLogs Module=proetojt OR Module=nxtransdirect OR
Module=sep_cid_coversheet OR Module=previewservice | chart count by Module, field3

It gives correct results to me. However it gives different set of results when my colleagues view it.

The issue is that field3 field does not come up when the other colleagues perform the search. We are unable to figure out how a particular field is displayed for one user and not for other. We have checked that field3 is not defined specifically for me in the following:

  1. Field Aliases
  2. Calculated Fields
  3. Field Extractions
  4. Field Transformations
  5. Sourcetype renaming
  6. Workflow actions

We are basically trying to find out that how the dashboard or search is picking up some fields which are displayed only to one user.

Any pointers to solve this issue would be helpful.

Regards,
Neeraj Gupta

Tags (2)
0 Karma

discoverneeraj
Explorer

The roles and the time period is same. While doing troubleshooting with the colleagues, we found the root cause of this issue. I deleted all my previous reports, extracted fields and dashboards.

Next when I performed the search, it was showing only few fields and then we extracted more fields from the search (using delimiter / regex).

When in the last you save this Report-XXXXXXX part i.e. extracted fields, you must give read permissions to all users explicitly.

Thanks for your time and effort to work on my issue.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi discoverneeraj,
the first thing to check is obviously what are roles of your users and that all your knowledge objects are shared for these roles, probably someone of them has different properties.

The second check to do is that the time period is the same in the compared searches (e.g. yesterday or last full hour), because if you use e.g. last hour (that means earliest=-60m latest=now), probably you'll have different results running searches in different times because you'll have different time periods.

Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...