Dashboards & Visualizations

Why are extracted fields not showing up for other users in dashboards, even after giving them read/write permissions?

meenuvn
Explorer

I've created a couple of field extractions and given read/write permissions to everyone and to appear in all apps.
But the dashboard referring these fields are not displaying these fields for other users. It can be viewed only by me as I created the field.

0 Karma

rwiley
Explorer

not sure if you got this fixed or not. i was having the same issue. the props was created in the user file only. i copid it out to the app and it is working for everyone.

user folder splunk/etc/users/user name extraction was created with/app created in/local/props.conf

copied to app folder

splunk/etc/apps/your app/local

0 Karma

sjohnson_splunk
Splunk Employee
Splunk Employee

It sounds like the extractions you created are still private. Did you promote them to the app level after you created them?

0 Karma

rwiley
Explorer

not sure if you got this fixed or not. i was having the same issue. the props was created in the user file only. i copid it out to the app and it is working for everyone.

user folder splunk/etc/users/user name extraction was created with/app created in/local/props.conf

copied to app folder

splunk/etc/apps/your app/local

0 Karma

ryanoconnor
Builder

What is the app context that the dashboard is in?

0 Karma

scottchytil
New Member

Same issue. I'm using Splunk Light Version 6.4.1. Users can create their own extractions that are only visible to them. Tried changing permissions on the user level extracted fields with no luck.

My local.meta from \etc\apps\search\metadata\
[props/DynamicExportCompare/REPORT-DynamicExportCompare2]
access = read : [ admin, user ], write : [ admin ]
export = system
owner = admin
version = 6.4.1
modtime = 1465571478.487277900

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...