@ssievert thanks for the reply. I have verified all the knowledge objects and their permissions, they are properly scoped. I took the search string for that dashboard, and ran in the search app of both user groups.
Still we are getting different results in both the Usergroups. And after reviewing from the input data, I can say that the results of the both the usergroups are incorrect.
Also, I have realized that we are getting this below warning (both in the search app and in the dashboard), which I think is one of the reasons for not getting correct output.
[subsearch]: [lgpbd022g.gso.abcd.com] Streamed search execute failed because: JournalSliceDirectory: Cannot seek to 0
Corresponding Search log:
INFO RetryManager - Peer="lgpbd0227.gso.abcd.com" at generation="1718653" was temporarily missing from the set of search peers. If the peer goes down while its information is missing, the search can return incomplete results. To remediate, run the search again.
I could not find the solution for this warning anywhere in the Splunk docs. Any help from your end will help us, as the users are facing this issue from couple of weeks. Please advise if you need anything more from my end for resolving this issue. Thanks in advance
... View more