<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Indexes are not available to select from &amp;quot;Available search indexes&amp;quot; during role creation since upgrade to 7.0.0 in Security</title>
    <link>https://community.splunk.com/t5/Security/Indexes-are-not-available-to-select-from-quot-Available-search/m-p/315175#M8233</link>
    <description>&lt;P&gt;Yes it worked!&lt;/P&gt;

&lt;P&gt;I got the authorize.conf from 6.6.3 version and placed it on the $SPLUNK_HOME/etc/apps/search/local/data/ui/manager folder and it fixed the issue after I debug/refreshed splunk Search Head.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;

&lt;P&gt;P.S. - I also had an issue while upgrading from 6.6.3 to 7.0.1 where I couldn't make any search. The fix was to enable Distributed Search again and restart the Search Head. The fix is here explained: &lt;A href="https://answers.splunk.com/answers/208043/unable-to-run-any-search-query-warn-search-filters.html"&gt;https://answers.splunk.com/answers/208043/unable-to-run-any-search-query-warn-search-filters.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Dec 2017 16:22:21 GMT</pubDate>
    <dc:creator>duartet</dc:creator>
    <dc:date>2017-12-19T16:22:21Z</dc:date>
    <item>
      <title>Indexes are not available to select from "Available search indexes" during role creation since upgrade to 7.0.0</title>
      <link>https://community.splunk.com/t5/Security/Indexes-are-not-available-to-select-from-quot-Available-search/m-p/315169#M8227</link>
      <description>&lt;P&gt;Since upgrading to splunk 7.0.0 I am not able to select our indexes from our indexcluster from "Available search indexes" during user role creation in the Splunk web gui. The indexes do exist and the Index-Role authorization is still working well using the authorize.conf files within the searchhead cluster.&lt;BR /&gt;
I have seen this has been a bug in the early versions of Splunk 6 and this looks like the same issue.&lt;BR /&gt;
Has anyone experienced this issue, before or in Splunk 7.0 ?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 13:25:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexes-are-not-available-to-select-from-quot-Available-search/m-p/315169#M8227</guid>
      <dc:creator>fboeje</dc:creator>
      <dc:date>2017-10-17T13:25:45Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes are not available to select from "Available search indexes" during role creation since upgrade to 7.0.0</title>
      <link>https://community.splunk.com/t5/Security/Indexes-are-not-available-to-select-from-quot-Available-search/m-p/315170#M8228</link>
      <description>&lt;P&gt;I have the exact same issue right after upgrade to 7.0&lt;BR /&gt;
- 1 Searchhead&lt;BR /&gt;
- 2 Clustered Indexers&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 14:10:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexes-are-not-available-to-select-from-quot-Available-search/m-p/315170#M8228</guid>
      <dc:creator>auradk</dc:creator>
      <dc:date>2017-10-17T14:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes are not available to select from "Available search indexes" during role creation since upgrade to 7.0.0</title>
      <link>https://community.splunk.com/t5/Security/Indexes-are-not-available-to-select-from-quot-Available-search/m-p/315171#M8229</link>
      <description>&lt;P&gt;I have the same issue, too.&lt;BR /&gt;
I have several testing environments.&lt;BR /&gt;
My 6.6.3 environment works fine. The searchhead can list all non-internal indexes in 'Available search indexes' column when I edit/create new roles.&lt;BR /&gt;
But my 7.0.0 environment can't list non-internal indexes by their names.&lt;BR /&gt;
Both environments have no local/indexes.conf which exists on the indexers.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2017 08:17:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexes-are-not-available-to-select-from-quot-Available-search/m-p/315171#M8229</guid>
      <dc:creator>witski</dc:creator>
      <dc:date>2017-10-18T08:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes are not available to select from "Available search indexes" during role creation since upgrade to 7.0.0</title>
      <link>https://community.splunk.com/t5/Security/Indexes-are-not-available-to-select-from-quot-Available-search/m-p/315172#M8230</link>
      <description>&lt;P&gt;Same here. Upgrade from 6.6.3 to 7.0.0.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2017 13:44:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexes-are-not-available-to-select-from-quot-Available-search/m-p/315172#M8230</guid>
      <dc:creator>jimt_mt</dc:creator>
      <dc:date>2017-10-23T13:44:35Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes are not available to select from "Available search indexes" during role creation since upgrade to 7.0.0</title>
      <link>https://community.splunk.com/t5/Security/Indexes-are-not-available-to-select-from-quot-Available-search/m-p/315173#M8231</link>
      <description>&lt;P&gt;I have a support case running on the issue.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2017 16:07:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexes-are-not-available-to-select-from-quot-Available-search/m-p/315173#M8231</guid>
      <dc:creator>auradk</dc:creator>
      <dc:date>2017-10-23T16:07:51Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes are not available to select from "Available search indexes" during role creation since upgrade to 7.0.0</title>
      <link>https://community.splunk.com/t5/Security/Indexes-are-not-available-to-select-from-quot-Available-search/m-p/315174#M8232</link>
      <description>&lt;P&gt;Splunk has identified this issue in SPL-145546, it is only a problem with the UI, so you should still be able to use authorize.conf to assign the index(es) to role(s). To temporarily workaround the issue, please follow the steps below.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Workaround:&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Step 1) Create a local directory in the search app on the SH with the correct permissions for splunkd to access i.e.&lt;/P&gt;

&lt;P&gt;$SPLUNK_HOME/etc/apps/search/local/data/ui/manager&lt;/P&gt;

&lt;P&gt;Step 2) Copy an old "authentication_roles.xml" file from "$SPLUNK_HOME/etc/apps/search/default/data/ui/manager" in any 6.x version or simply download a new 6.x version of Splunk and extract the file there, then place it into the folder created in step 1.&lt;/P&gt;

&lt;P&gt;Step 3) Refresh the SH configuration with debug refresh via the web browser:&lt;/P&gt;

&lt;P&gt;http://:8000/en-US/debug/refresh&lt;/P&gt;

&lt;P&gt;Step 4) Create a new role on the SH and you should see all your indexes configured on the index cluster. &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Note: In the workaround provided above, there is a known issue (SPL-146171) where only 1000 indexes is displayed in the UI. If you have more than 1000 indexes, you should modify authorize.conf to add the index(es) to role(s) instead&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:41:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexes-are-not-available-to-select-from-quot-Available-search/m-p/315174#M8232</guid>
      <dc:creator>rjteh_splunk</dc:creator>
      <dc:date>2020-09-29T16:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes are not available to select from "Available search indexes" during role creation since upgrade to 7.0.0</title>
      <link>https://community.splunk.com/t5/Security/Indexes-are-not-available-to-select-from-quot-Available-search/m-p/315175#M8233</link>
      <description>&lt;P&gt;Yes it worked!&lt;/P&gt;

&lt;P&gt;I got the authorize.conf from 6.6.3 version and placed it on the $SPLUNK_HOME/etc/apps/search/local/data/ui/manager folder and it fixed the issue after I debug/refreshed splunk Search Head.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;

&lt;P&gt;P.S. - I also had an issue while upgrading from 6.6.3 to 7.0.1 where I couldn't make any search. The fix was to enable Distributed Search again and restart the Search Head. The fix is here explained: &lt;A href="https://answers.splunk.com/answers/208043/unable-to-run-any-search-query-warn-search-filters.html"&gt;https://answers.splunk.com/answers/208043/unable-to-run-any-search-query-warn-search-filters.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2017 16:22:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexes-are-not-available-to-select-from-quot-Available-search/m-p/315175#M8233</guid>
      <dc:creator>duartet</dc:creator>
      <dc:date>2017-12-19T16:22:21Z</dc:date>
    </item>
  </channel>
</rss>

