<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Events are breaking only for admin role and they are not breaking for any other user roles in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Events-are-breaking-only-for-admin-role-and-they-are-not/m-p/569283#M10181</link>
    <description>&lt;P&gt;In one of our Single Instance (test) We faced the same issue. Then we found that in metadata permission was not given for all the users. After updating the metadata it started working fine for all the users.&lt;/P&gt;&lt;P&gt;Now the same app we placed it in our production distributed environment but it is still not working ,the events are not breaking for non admin users.&lt;/P&gt;&lt;P&gt;It was suggested that we place splunk ta-nix in all our instances (Indexers,Forwarders,DS).we tried that as well.&lt;/P&gt;&lt;P&gt;What else can we try to break the events for non admin users as well?&lt;/P&gt;&lt;P&gt;Version of app is 8.3.0&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/129407"&gt;@thambisetty&lt;/a&gt;&amp;nbsp; ++++ any suggestions pls&lt;/P&gt;</description>
    <pubDate>Fri, 01 Oct 2021 08:08:02 GMT</pubDate>
    <dc:creator>Ashwini008</dc:creator>
    <dc:date>2021-10-01T08:08:02Z</dc:date>
    <item>
      <title>Events are breaking only for admin role and they are not breaking for any other user roles</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Events-are-breaking-only-for-admin-role-and-they-are-not/m-p/569065#M10148</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Events for simple query index=os sourcetype=cpu are not breaking for users without admin role.&lt;/P&gt;&lt;P&gt;All other user without admin role&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ashwini008_3-1632987801062.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16217i34A2226C618E5817/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Ashwini008_3-1632987801062.png" alt="Ashwini008_3-1632987801062.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;For user with admin role&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ashwini008_4-1632987878556.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16218i9A046EACF5B39DFB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Ashwini008_4-1632987878556.png" alt="Ashwini008_4-1632987878556.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;What could be the reason? Any suggestions please&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 07:46:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Events-are-breaking-only-for-admin-role-and-they-are-not/m-p/569065#M10148</guid>
      <dc:creator>Ashwini008</dc:creator>
      <dc:date>2021-09-30T07:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: Events are breaking only for admin role and they are not breaking for any other user roles</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Events-are-breaking-only-for-admin-role-and-they-are-not/m-p/569079#M10156</link>
      <description>Hi&lt;BR /&gt;is this a single node installation or distributed?&lt;BR /&gt;Quite probably there is some KO which affects only in admin role?&lt;BR /&gt;r. Ismo</description>
      <pubDate>Thu, 30 Sep 2021 08:50:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Events-are-breaking-only-for-admin-role-and-they-are-not/m-p/569079#M10156</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-09-30T08:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: Events are breaking only for admin role and they are not breaking for any other user roles</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Events-are-breaking-only-for-admin-role-and-they-are-not/m-p/569093#M10164</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;It is distributed environment.Please can you brief me what is KO&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 10:08:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Events-are-breaking-only-for-admin-role-and-they-are-not/m-p/569093#M10164</guid>
      <dc:creator>Ashwini008</dc:creator>
      <dc:date>2021-09-30T10:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: Events are breaking only for admin role and they are not breaking for any other user roles</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Events-are-breaking-only-for-admin-role-and-they-are-not/m-p/569095#M10165</link>
      <description>&lt;P&gt;Knowledge Object&lt;/P&gt;&lt;P&gt;And it would indeed look like a permission problem but I don't recall any search-time settings affecting event breaking. The events are separated at ingest time. Are you sure nothing changed on your sources' side or in ingest settings? (You show events from two different days)&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 10:14:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Events-are-breaking-only-for-admin-role-and-they-are-not/m-p/569095#M10165</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-09-30T10:14:13Z</dc:date>
    </item>
    <item>
      <title>Re: Events are breaking only for admin role and they are not breaking for any other user roles</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Events-are-breaking-only-for-admin-role-and-they-are-not/m-p/569104#M10166</link>
      <description>&lt;P&gt;You are probably using this one&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/833/" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/833/&lt;/A&gt;&amp;nbsp;?&lt;/P&gt;&lt;P&gt;Have you installed it as described on instructions? And is this issue only with this one source type or other too?&lt;/P&gt;&lt;P&gt;Basically if this has installed as expected and all those events are collected after that those should be show as exactly same way independent of user/role. When installation and indexing has done right those should be indexed as events in splunk.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you do a new query with exactly same time period like earliest="mm/dd/yyyy:HH:MM:SS" latest="mm/dd:yyyy:HH+1:MM:SS" and check if those are still differing? Check also if there is any difference between hosts where those are collected.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;&lt;P&gt;KO &amp;lt;=&amp;gt; Knowledge Object&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 10:38:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Events-are-breaking-only-for-admin-role-and-they-are-not/m-p/569104#M10166</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-09-30T10:38:13Z</dc:date>
    </item>
    <item>
      <title>Re: Events are breaking only for admin role and they are not breaking for any other user roles</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Events-are-breaking-only-for-admin-role-and-they-are-not/m-p/569105#M10167</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;No nothing has changed. &lt;SPAN&gt;(You show events from two different days) &amp;gt;&amp;gt;&lt;/SPAN&gt;It is different timezone .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For Admin role the events are breaking properly.Permission is given for all the users in local.meta&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 10:38:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Events-are-breaking-only-for-admin-role-and-they-are-not/m-p/569105#M10167</guid>
      <dc:creator>Ashwini008</dc:creator>
      <dc:date>2021-09-30T10:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: Events are breaking only for admin role and they are not breaking for any other user roles</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Events-are-breaking-only-for-admin-role-and-they-are-not/m-p/569120#M10168</link>
      <description>&lt;P&gt;It's interesting though because it's not that easy to split an event in search-time. There must be some indeed some KO affecting your search but it's hard to say which one without listing them all and manually verifying.&lt;/P&gt;&lt;P&gt;Remember that instead of clicking through the UI you can list various KO types with REST calls. Then you can check the permissions fields (you'll definitely want to limit list of fields returned from REST because there are typically up to several hundred fields).&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 12:12:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Events-are-breaking-only-for-admin-role-and-they-are-not/m-p/569120#M10168</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-09-30T12:12:25Z</dc:date>
    </item>
    <item>
      <title>Re: Events are breaking only for admin role and they are not breaking for any other user roles</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Events-are-breaking-only-for-admin-role-and-they-are-not/m-p/569283#M10181</link>
      <description>&lt;P&gt;In one of our Single Instance (test) We faced the same issue. Then we found that in metadata permission was not given for all the users. After updating the metadata it started working fine for all the users.&lt;/P&gt;&lt;P&gt;Now the same app we placed it in our production distributed environment but it is still not working ,the events are not breaking for non admin users.&lt;/P&gt;&lt;P&gt;It was suggested that we place splunk ta-nix in all our instances (Indexers,Forwarders,DS).we tried that as well.&lt;/P&gt;&lt;P&gt;What else can we try to break the events for non admin users as well?&lt;/P&gt;&lt;P&gt;Version of app is 8.3.0&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/129407"&gt;@thambisetty&lt;/a&gt;&amp;nbsp; ++++ any suggestions pls&lt;/P&gt;</description>
      <pubDate>Fri, 01 Oct 2021 08:08:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Events-are-breaking-only-for-admin-role-and-they-are-not/m-p/569283#M10181</guid>
      <dc:creator>Ashwini008</dc:creator>
      <dc:date>2021-10-01T08:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: Events are breaking only for admin role and they are not breaking for any other user roles</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Events-are-breaking-only-for-admin-role-and-they-are-not/m-p/571211#M10358</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222977"&gt;@Ashwini008&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I think there is a problem on KV_MODE settings on your search head for non-admin users. It should be "multi".&lt;/P&gt;&lt;P&gt;You may have another props.conf that has &amp;nbsp;[cpu] stanza inside which overwrites the&amp;nbsp;Splunk_TA_nix app props.&lt;/P&gt;&lt;P&gt;Could you please run the below command on your search head and see if this exists? If yes you will see on which config file you have a second cpu stanza that has wrong KV_MODE config. &amp;nbsp;You may see KV_MODE setting which is different than multi.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/opt/splunk/bin/splunk btool props list cpu --debug&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Oct 2021 16:53:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Events-are-breaking-only-for-admin-role-and-they-are-not/m-p/571211#M10358</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-10-16T16:53:40Z</dc:date>
    </item>
  </channel>
</rss>

