Security

Different Performance using admin user or a user with only user role

aniello_cerrato
Path Finder

Hi,

I have different Performance using admin user and a user with only user role.

The query is very simple, below the xml of panel.

What could be the root cause of this behaviour?

Thanks,
A

row>

Scarti per Prodotto



sourcetype="cx_import_req_prod" REQUEST_TYPE!="Attivazione" STATUS_CD="Errore" | dedup ROW_ID | stats count by segmento
$last_upd.earliest$
$last_upd.latest$
1

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi aniello_cerrato,
you should verify if this user has many active searches at the same time: the only thing I can think is that the role of this user has a maximum number of executable searches less than admin role, so when he executes too many searches the last are queued.
Bye.
Giuseppe

View solution in original post

0 Karma

aniello_cerrato
Path Finder

Hi Giuseppe,

how can verify the number executable searches for my user?

Thanks,
Aniello

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi aniello_cerrato,
you should verify if this user has many active searches at the same time: the only thing I can think is that the role of this user has a maximum number of executable searches less than admin role, so when he executes too many searches the last are queued.
Bye.
Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

go to Settings -- Access Control -- Roles -- your role
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...