Different roles and groups see different data in the dashboard.
OpenCTI Version : 6.1.10
In the photo below, the left side is the dashboard screen for a user with the Administrator, Default Role and Group,
on the right is the dashboard for a user with the External role and Group.
.
.
.
The data that exists in the platform is the same, so I don't understand why the two dashboards show different data.
Is this a bug?
Your answer would be greatly appreciated.
@misohouse to help you out, can you provide us with:
- capabilities associated with each role
- marking associated with each group
- organisation associated with each user (to which organisation they belong)
- if you have set a platform organisation (visible in setting/security/policies)
@nino-filigran
Here is information about role and group.
.
.
.
[1] Administrator Role
.
.
[2] Default Role
.
.
[3] External Role
.
.
[4] External account information
.
.
[5] Administrator account information
.
.
If you need more information, I'll add it.
Can you provide the allowed marking fro your groups?
@nino-filigran
Sure, here it is.
.
.
.
[6] Administrator Groups
.
.
[7] Default Groups
.
.
[8] External Groups
To recap my understanding, users of external group (first screenshot on the right in your ticket) see less info than users from default/admin (first screenshot on the left).
Based on your responses and screenshots, the reason is simple: your external group have less marking than your default admin (in the "allowed markings"). They cannot see anything above TLP:AMBER, which is the reason you have some discrepencies.
@nino-filigran
If you're right, shouldn't we rather see less information in the External account?
If you look at the screenshot I posted at the very beginning, it actually shows less information in the Administrator account (the dashboard shows no data).
Note that most data is currently written as TLP:GREEN and TLP:CLEAR.
Am I misunderstanding something?
You're completly right, sorry about this, I've mixed up your dashboards and focused on the numbers widgets. I'll keep investigating!
@misohouse sorry for not following up this earlier. Do you still encounter the issue?
@nino-filigran
Hi, I'm still experiencing the same issue and waiting for a solution.
(Administrator)
(External)
@misohouse we're still trying to understand what could be the issue, however, we struggle with this since we're not able to reproduce at all your situation. I guess since then you've upgraded to most recent version, right? And tried to clear your local storage?
Hi @misohouse when you have empty widget with your administrator do you have any log ? Could you provide a support package after accessing the dashboard with your admin ?
@misohouse we're still trying to understand what could be the issue, however, we struggle with this since we're not able to reproduce at all your situation. I guess since then you've upgraded to most recent version, right? And tried to clear your local storage?
Yes I am currently using the latest version, and the local storage is not being cleared because it has existing data.
We're still having issue on our side to reproduce the issue, making the investigation stuggling for information. Could you please provide a support package as requested above when you have an emtpy widget?
@nino-filigran
Ah I solved the problem!
I changed the date type to “Technical date” in the settings on the bottom right of the platform and it looks fine :)
I'm glad to hear it @misohouse thanks for informing us! I'm closing the bug as a result. Feel free to re-open it if you still have an issue/comment.