Hi
our reported spice usage shot up to 183 gb overnight. We’ve been running with daily refreshes for almost 2 years and have never come close to the 40gb. In fact when i went through every dataset and added up all of our spice usage it is less than 4gb. I also checked to be sure that there were no spikes in ingested rows. and now my nightly refreshes are failing.
1/ do you have access to all datasets within your Quick Sight environment ?
2/ If you have others Authors who can create datasets and they are not shared with you, you will not be able to view them
3/ If you have access to Cloudwatch, possibly that give you an idea of the ingestions as well [ Metrics - Amazon QuickSight ]
thanks @Koushik_Muthanna
yes i am our sites sole administrator and can see all datasets - i will check cloudwatch to see if it is different from what the console is reporting
@Koushik_Muthanna
im attaching some screenshots. i can see in cloudwatch when the event happened but i cant drill down into what dataset or datasets might have caused the spike. Maybe you can help me figure this out? I’m also attaching a screen shot of a typical data set to show the console output.
@Koushik_Muthanna
regarding your original question - i might be mistaken - i am and administrator and i assume i can see all datasets, analysis and dashboards created by my users. I have several users in role Author, i created a group for them and i gave Viewer access to specific datasets in that group. I didnt think they could edit those datasets or create new ones, but want to confirm.
Thanks
Hi @Koushik_Muthanna
apologies for spamming the thread - but i figured it out, and i wanted to share my experience. Quicksight admins beware
My user with Author role and with View access to 4 data sets was able to create a new dataset that simply joined 2 of the datasets that they had access to. These two datasets (489k rows 184mb and 602k rows 218mb) do not have a common key, so i am guessing that the spice engine generated the Cartesian Product of the two datasets because the resulting dataset contained 173,174,929 mil rows. I realize 489k * 602k is well over 173 mil but anyway - regardless - the damage was done it used up 183gb well over our spice limit.
I didnt initially see it b/c i thought i could see all datasets in my console view (there is a owner column) and they named the new dataset the same exact name as one of the datasets they had access to. And they now had Owner access to the new dataset. I only found it in the Admin console Manage Assets tab looking through each of my users and what they had access to.
I will say that there is a very confusing Administrative View. Go to → Manage Assets → User or Group assets → . The filters at the top of the table have a Permissions dropdown - but the options are confusing
Owner, Owner + Viewer, Sole Owner.
Specifically what is Owner + Viewer? When you grant permissions you give either Owner OR Viewer - so this list is not very helpful - are you an owner or a viewer? Maybe im not understanding.
So the good news is no bug, no issue other than my analyst not fully understanding the data they were granted access to and managed to shoot ourselves in the foot. However, Is it possible to remove an Authors ability to create datasets? I want them to build analysis and visuals and create calculated fields etc with the datasets they have access to, but not new datasets.
You can restrict others from creating datasets using your source dataset with the following option.
The above would restrict you from using the dataset in other dataset including you.
So, the other option is to use Custom Permissions to restrict dataset creation. There is already a post in the community which I give you reference to.