<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk could not update permissions for resource data/transforms/lookups in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-could-not-update-permissions-for-resource-data-transforms/m-p/563227#M15526</link>
    <description>&lt;P&gt;For the record, I ran into a case, when I run into the error message.&lt;BR /&gt;It was when I needed to replace an existing csv file for lookup.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I forgot to delete the existing one, and hoping the new file will override the existing one.&lt;/P&gt;&lt;P&gt;It turned out that Splunk just complained without clearer indication of my offense.&lt;/P&gt;&lt;P&gt;It would have been more helpful with more concrete error diagnose.&lt;/P&gt;</description>
    <pubDate>Fri, 13 Aug 2021 18:12:46 GMT</pubDate>
    <dc:creator>yshen</dc:creator>
    <dc:date>2021-08-13T18:12:46Z</dc:date>
    <item>
      <title>Splunk could not update permissions for resource data/transforms/lookups</title>
      <link>https://community.splunk.com/t5/Security/Splunk-could-not-update-permissions-for-resource-data-transforms/m-p/72558#M2388</link>
      <description>&lt;P&gt;I tried to change in permissions from private to Global of lookup table and definition- and automatic lookups- in 2 indexers and header server.&lt;BR /&gt;
(There are 3 splunks(Linux Redhat 6.3). 2 indexers(2 servers physically) and 1 header(1 server physically).)&lt;BR /&gt;
There show no problem in 2 indexers, but the header servers shows the following error messages:&lt;/P&gt;

&lt;P&gt;"Splunk could not update permissions for resource data/transforms/lookups [HTTP 409][{'text':'Cannot overwrite existing app object','code':None, 'type':'ERROR'}] "&lt;/P&gt;

&lt;P&gt;What would you suggest to solve this problem or error?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Dec 2012 07:18:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-could-not-update-permissions-for-resource-data-transforms/m-p/72558#M2388</guid>
      <dc:creator>joy76</dc:creator>
      <dc:date>2012-12-24T07:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk could not update permissions for resource data/transforms/lookups</title>
      <link>https://community.splunk.com/t5/Security/Splunk-could-not-update-permissions-for-resource-data-transforms/m-p/72559#M2389</link>
      <description>&lt;P&gt;I just ran into this issue too. Can anyone explain why this happens..&lt;/P&gt;

&lt;P&gt;FOr me i added a extraction to props.conf and I get this error when trying to change permission on the new extraction&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2013 12:39:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-could-not-update-permissions-for-resource-data-transforms/m-p/72559#M2389</guid>
      <dc:creator>paul_1994</dc:creator>
      <dc:date>2013-03-13T12:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk could not update permissions for resource data/transforms/lookups</title>
      <link>https://community.splunk.com/t5/Security/Splunk-could-not-update-permissions-for-resource-data-transforms/m-p/72560#M2390</link>
      <description>&lt;P&gt;Experiencing this today trying to change permissions from private to global on a saved search.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2013 13:58:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-could-not-update-permissions-for-resource-data-transforms/m-p/72560#M2390</guid>
      <dc:creator>aarcro</dc:creator>
      <dc:date>2013-04-30T13:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk could not update permissions for resource data/transforms/lookups</title>
      <link>https://community.splunk.com/t5/Security/Splunk-could-not-update-permissions-for-resource-data-transforms/m-p/72561#M2391</link>
      <description>&lt;P&gt;I am also getting this error can anyone help?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2013 15:35:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-could-not-update-permissions-for-resource-data-transforms/m-p/72561#M2391</guid>
      <dc:creator>mookiie2005</dc:creator>
      <dc:date>2013-08-01T15:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk could not update permissions for resource data/transforms/lookups</title>
      <link>https://community.splunk.com/t5/Security/Splunk-could-not-update-permissions-for-resource-data-transforms/m-p/72562#M2392</link>
      <description>&lt;P&gt;I just had this issue and I found that we had two instances of the same field extraction from two different users.  If you tried to make one global you would not have an issue when you try and make the second, of the same name, global you receive the error described above.  Hope this helps someone else.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2013 15:40:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-could-not-update-permissions-for-resource-data-transforms/m-p/72562#M2392</guid>
      <dc:creator>mookiie2005</dc:creator>
      <dc:date>2013-08-01T15:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk could not update permissions for resource data/transforms/lookups</title>
      <link>https://community.splunk.com/t5/Security/Splunk-could-not-update-permissions-for-resource-data-transforms/m-p/72563#M2393</link>
      <description>&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2013 04:22:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-could-not-update-permissions-for-resource-data-transforms/m-p/72563#M2393</guid>
      <dc:creator>joy76</dc:creator>
      <dc:date>2013-08-08T04:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk could not update permissions for resource data/transforms/lookups</title>
      <link>https://community.splunk.com/t5/Security/Splunk-could-not-update-permissions-for-resource-data-transforms/m-p/72564#M2394</link>
      <description>&lt;P&gt;similar problem with permission modification / update for tags.&lt;/P&gt;

&lt;P&gt;in Tags » List by field value pair i was getting --Private | Permissions unable to update to Global&lt;BR /&gt;
but &lt;/P&gt;

&lt;P&gt;in Tags » All unique tag objects, it was showing --Global | Permissions&lt;/P&gt;

&lt;P&gt;I ran to update the tags.conf with&lt;BR /&gt;
http(s)://yoursplunkhost:8000/debug/refresh?entity=admin/fvtags&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Give app level permissions:&lt;/STRONG&gt;&lt;BR /&gt;
 1. In /opt/splunk/etc/apps/xx/metadata&lt;BR /&gt;
access = read : [ * ], write : [ admin,power ]&lt;BR /&gt;
export = system&lt;BR /&gt;
      OR &lt;BR /&gt;
 2.  From Apps drop down apps--&amp;gt; manage Apps.&lt;BR /&gt;
 select the respective app and give global permission and u are there.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2014 11:27:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-could-not-update-permissions-for-resource-data-transforms/m-p/72564#M2394</guid>
      <dc:creator>neelamssantosh</dc:creator>
      <dc:date>2014-07-10T11:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk could not update permissions for resource data/transforms/lookups</title>
      <link>https://community.splunk.com/t5/Security/Splunk-could-not-update-permissions-for-resource-data-transforms/m-p/72565#M2395</link>
      <description>&lt;P&gt;I had the same error for a view I created. I couldn't set it to App/Global from Private. Also, the metadata didn't include any rule of the view, which was placed in an app. I moved it to a different App and then I was able to change the permissions as it is supposed to be&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2015 07:38:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-could-not-update-permissions-for-resource-data-transforms/m-p/72565#M2395</guid>
      <dc:creator>tmnuclear</dc:creator>
      <dc:date>2015-04-22T07:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk could not update permissions for resource data/transforms/lookups</title>
      <link>https://community.splunk.com/t5/Security/Splunk-could-not-update-permissions-for-resource-data-transforms/m-p/72566#M2396</link>
      <description>&lt;P&gt;Brilliant, thanks, would be helpful if splunk actually said what the problem was rather than just failing with Error=None&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2019 11:30:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-could-not-update-permissions-for-resource-data-transforms/m-p/72566#M2396</guid>
      <dc:creator>stephenoleary</dc:creator>
      <dc:date>2019-10-08T11:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk could not update permissions for resource data/transforms/lookups</title>
      <link>https://community.splunk.com/t5/Security/Splunk-could-not-update-permissions-for-resource-data-transforms/m-p/563227#M15526</link>
      <description>&lt;P&gt;For the record, I ran into a case, when I run into the error message.&lt;BR /&gt;It was when I needed to replace an existing csv file for lookup.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I forgot to delete the existing one, and hoping the new file will override the existing one.&lt;/P&gt;&lt;P&gt;It turned out that Splunk just complained without clearer indication of my offense.&lt;/P&gt;&lt;P&gt;It would have been more helpful with more concrete error diagnose.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 18:12:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-could-not-update-permissions-for-resource-data-transforms/m-p/563227#M15526</guid>
      <dc:creator>yshen</dc:creator>
      <dc:date>2021-08-13T18:12:46Z</dc:date>
    </item>
  </channel>
</rss>

