<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dbmon permissions issue in Security</title>
    <link>https://community.splunk.com/t5/Security/dbmon-permissions-issue/m-p/140182#M14570</link>
    <description>&lt;P&gt;The  version of DB Connect I'm using is 1.1.3  with splunk enterprise 6.0.3&lt;/P&gt;</description>
    <pubDate>Wed, 23 Apr 2014 15:38:36 GMT</pubDate>
    <dc:creator>mjones414</dc:creator>
    <dc:date>2014-04-23T15:38:36Z</dc:date>
    <item>
      <title>dbmon permissions issue</title>
      <link>https://community.splunk.com/t5/Security/dbmon-permissions-issue/m-p/140181#M14569</link>
      <description>&lt;P&gt;Ever since upgrading splunk DB connect to a version that supports the dbx_user role I've been working out odd permissions issues and so far I've been able to get most of them sans one.&lt;/P&gt;

&lt;P&gt;I had a decent handful of db inputs created prior to upgrading to a version of the app with dbx_user defined.  I've since retroactively added dbx_user to all the users needing access and they can manage their database connections fine but they cannot create new or modify their existing dbmon inputs whether they are tail or dumps.&lt;/P&gt;

&lt;P&gt;The error they are receiving is:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;There was an error retrieving the configuration, can not process this page.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Splunk administrators are not having any issues. &lt;/P&gt;

&lt;P&gt;the current local.meta for db connect is as follows:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[]
access = read : [ dbx_user, admin ], write : [ admin ]

### Manager ###

[manager]
export = system

[manager/databases]
export = system

[manager/dbmon]
export = system
access = read : [ admin , dbx_user ], write : [ admin , dbx_user ]

[manager/dblookups]
export = system
access = read : [ admin ,dbx_user  ], write : [ admin ,dbx_user ]

### Commands ###

[commands/dbquery]
export = system

[commands/dbinput]
export = system

[commands/dbinfo]
export = system

[commands/dboutput]
export = system

[commands/dbmonpreview]
export = none
access = read : [ admin, dbx_user ], write : [ admin ]


### Other settings ###

[inputs/dbmon-*]

[inputs]
access = read : [ dbx_user, admin ], write : [ admin , dbx_user]

[transforms]
access = read : [ dbx_user, admin ], write : [ admin , dbx_user]

[props]
export = system

[transforms]
export = system

[eventtypes]
export = system

[lookups]
export = system

[searchscripts]
export = system

[database]
access = read : [ dbx_user, admin ], write : [ admin , dbx_user]

[dblookup]
access = read : [ dbx_user, admin ], write : [ admin , dbx_user]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 23 Apr 2014 15:36:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/dbmon-permissions-issue/m-p/140181#M14569</guid>
      <dc:creator>mjones414</dc:creator>
      <dc:date>2014-04-23T15:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: dbmon permissions issue</title>
      <link>https://community.splunk.com/t5/Security/dbmon-permissions-issue/m-p/140182#M14570</link>
      <description>&lt;P&gt;The  version of DB Connect I'm using is 1.1.3  with splunk enterprise 6.0.3&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2014 15:38:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/dbmon-permissions-issue/m-p/140182#M14570</guid>
      <dc:creator>mjones414</dc:creator>
      <dc:date>2014-04-23T15:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: dbmon permissions issue</title>
      <link>https://community.splunk.com/t5/Security/dbmon-permissions-issue/m-p/140183#M14571</link>
      <description>&lt;P&gt;I think the problem is because creating an input requires the admin_all_objects permission, which as the name implies means having essentially unlimited access.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2014 17:40:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/dbmon-permissions-issue/m-p/140183#M14571</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2014-04-23T17:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: dbmon permissions issue</title>
      <link>https://community.splunk.com/t5/Security/dbmon-permissions-issue/m-p/140184#M14572</link>
      <description>&lt;P&gt;Wow..  That's a bummer &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;  I wonder if there is any way to work this in as a feature request to have that tied to the dbx_user role...&lt;/P&gt;

&lt;P&gt;Thank you!  I will mark as answered until a way has been discovered. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2014 17:45:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/dbmon-permissions-issue/m-p/140184#M14572</guid>
      <dc:creator>mjones414</dc:creator>
      <dc:date>2014-04-23T17:45:10Z</dc:date>
    </item>
  </channel>
</rss>

