<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Slack Notification Alert: Seem to require admin privlidges to send alert per event in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Slack-Notification-Alert-Seem-to-require-admin-privlidges-to/m-p/459862#M56590</link>
    <description>&lt;P&gt;Through trial and error, discovered that you need to add &lt;STRONG&gt;admin_all_objects&lt;/STRONG&gt; permissions to all users that use this feature.  This appears to be something fairly new and, IMO kinda dangerous.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 21:56:23 GMT</pubDate>
    <dc:creator>sharkannon</dc:creator>
    <dc:date>2020-09-29T21:56:23Z</dc:date>
    <item>
      <title>Slack Notification Alert: Seem to require admin privlidges to send alert per event</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Slack-Notification-Alert-Seem-to-require-admin-privlidges-to/m-p/459861#M56589</link>
      <description>&lt;P&gt;Since upgrading to splunk 7.2.0 (we were on 7.0.0 before), Alerts that were created by non admin users that use the "For each result" trigger for alerts don't seem to go through with the splunk plugin.&lt;/P&gt;

&lt;P&gt;We tried attaching both the slack alert and the email alerts, and users receive the emails correctly, but the slack alerts "disappear".  I can assign the alert to a user with Admin OR promote the user to Admin and the alert seems to start working fine.&lt;/P&gt;

&lt;P&gt;Do you know what permissions I may need to update our users with, or if this is a bug in the app?&lt;/P&gt;

&lt;P&gt;The only thing I can see that MAY coincide is an error that says:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Error in 'sendalert' command: sendmodalert: Cannot access results_file: '/opt/splunk/var/run/splunk/dispatch/scheduler__USER__search__testalert_at_1541565840_19/per_result_alert/tmp_5.csv.gz'. Permission denied.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Other than that I can't seem to find anything in the logs that may be associated.  File permissions and everything are correct.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2018 05:02:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Slack-Notification-Alert-Seem-to-require-admin-privlidges-to/m-p/459861#M56589</guid>
      <dc:creator>sharkannon</dc:creator>
      <dc:date>2018-11-07T05:02:07Z</dc:date>
    </item>
    <item>
      <title>Re: Slack Notification Alert: Seem to require admin privlidges to send alert per event</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Slack-Notification-Alert-Seem-to-require-admin-privlidges-to/m-p/459862#M56590</link>
      <description>&lt;P&gt;Through trial and error, discovered that you need to add &lt;STRONG&gt;admin_all_objects&lt;/STRONG&gt; permissions to all users that use this feature.  This appears to be something fairly new and, IMO kinda dangerous.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:56:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Slack-Notification-Alert-Seem-to-require-admin-privlidges-to/m-p/459862#M56590</guid>
      <dc:creator>sharkannon</dc:creator>
      <dc:date>2020-09-29T21:56:23Z</dc:date>
    </item>
    <item>
      <title>Re: Slack Notification Alert: Seem to require admin privlidges to send alert per event</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Slack-Notification-Alert-Seem-to-require-admin-privlidges-to/m-p/459863#M56591</link>
      <description>&lt;P&gt;If it used to work and now doesn't, you should file a support case.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2018 18:20:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Slack-Notification-Alert-Seem-to-require-admin-privlidges-to/m-p/459863#M56591</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-11-07T18:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: Slack Notification Alert: Seem to require admin privlidges to send alert per event</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Slack-Notification-Alert-Seem-to-require-admin-privlidges-to/m-p/459864#M56592</link>
      <description>&lt;P&gt;Any update on this?  We are running into the same issue with 7.2.1.  This is a serious issue if users need the AAO capability to do this.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 13:29:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Slack-Notification-Alert-Seem-to-require-admin-privlidges-to/m-p/459864#M56592</guid>
      <dc:creator>paimonsoror</dc:creator>
      <dc:date>2019-01-09T13:29:21Z</dc:date>
    </item>
    <item>
      <title>Re: Slack Notification Alert: Seem to require admin privlidges to send alert per event</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Slack-Notification-Alert-Seem-to-require-admin-privlidges-to/m-p/459865#M56593</link>
      <description>&lt;P&gt;For those wondering, this was introduced in 7.2.1 and is apparently resolved in 7.2.4&lt;/P&gt;

&lt;P&gt;See &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.3/ReleaseNotes/Knownissues"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.3/ReleaseNotes/Knownissues&lt;/A&gt; - SPL-163315 &amp;amp; SPL-163882&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 02:21:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Slack-Notification-Alert-Seem-to-require-admin-privlidges-to/m-p/459865#M56593</guid>
      <dc:creator>serialmonkey</dc:creator>
      <dc:date>2019-02-08T02:21:10Z</dc:date>
    </item>
  </channel>
</rss>

