All Apps and Add-ons

Dashbord shows different results to different users

discoverneeraj
Explorer

Hello All,
I executed the following search and saved it as a dashboard:

index="tcpr-dispatcher" host="orl_displogs" sourcetype=DispatcherLogs Module=proetojt OR Module=nxtransdirect OR
Module=sep_cid_coversheet OR Module=previewservice | chart count by Module, field3

It gives correct results to me. However it gives different set of results when my colleagues view it.

The issue is that field3 field does not come up when the other colleagues perform the search. We are unable to figure out how a particular field is displayed for one user and not for other. We have checked that field3 is not defined specifically for me in the following:

  1. Field Aliases
  2. Calculated Fields
  3. Field Extractions
  4. Field Transformations
  5. Sourcetype renaming
  6. Workflow actions

We are basically trying to find out that how the dashboard or search is picking up some fields which are displayed only to one user.

Any pointers to solve this issue would be helpful.

Regards,
Neeraj Gupta

Tags (2)
0 Karma

discoverneeraj
Explorer

The roles and the time period is same. While doing troubleshooting with the colleagues, we found the root cause of this issue. I deleted all my previous reports, extracted fields and dashboards.

Next when I performed the search, it was showing only few fields and then we extracted more fields from the search (using delimiter / regex).

When in the last you save this Report-XXXXXXX part i.e. extracted fields, you must give read permissions to all users explicitly.

Thanks for your time and effort to work on my issue.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi discoverneeraj,
the first thing to check is obviously what are roles of your users and that all your knowledge objects are shared for these roles, probably someone of them has different properties.

The second check to do is that the time period is the same in the compared searches (e.g. yesterday or last full hour), because if you use e.g. last hour (that means earliest=-60m latest=now), probably you'll have different results running searches in different times because you'll have different time periods.

Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...