<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk App for Infrastructure: You do not have permissions to access objects of user in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-App-for-Infrastructure-You-do-not-have-permissions-to/m-p/506251#M2234</link>
    <description>&lt;P&gt;I have not tried 2.1.0, only the older 2.0.x, we used the collectd standard install with minimal changes...&lt;/P&gt;</description>
    <pubDate>Fri, 26 Jun 2020 05:53:21 GMT</pubDate>
    <dc:creator>gjanders</dc:creator>
    <dc:date>2020-06-26T05:53:21Z</dc:date>
    <item>
      <title>Splunk App for Infrastructure: You do not have permissions to access objects of user</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-App-for-Infrastructure-You-do-not-have-permissions-to/m-p/503886#M1869</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am relatively new to Splunk Enterprise and recently started with the&amp;nbsp;App for Infrastructure to monitor some CentOS 7.4 servers. Via the auto-deployment script through the "Add-Data" tab I tried to deploy the collection. This failed however, since the Splunk collectd plugin does not seem to recognize the libcurl library which resulted in error code 6, could resolve hostname although a regular curl works (adding a sample metric through HEC).&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the end I got around this by using the old method http_write plugin. So I have now the metrics in, but it does not seem to be working natively with the infrastructure app. When opening the server in the app (it is recognized in the investigate tab), then the metrics are empty in the overview sub-tab. When I click on analyze, it states the following: "You do not have permissions to access objects of user=x". The panels give the following text: "&lt;SPAN&gt;There is no data available for cpu.system. To see data on the chart, select a different time range, edit filters, or check with your administrator about user permissions."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;This seems clearly like an rights issue, because the cpu.* metrics are actually there. I have however no clue what the Infrastructure app is expecting in terms of rights / users. As far as my knowledge goes, this is all default. I am sending the data to the default em_metrics index from the&amp;nbsp;Infrastructure app with sourcetype collectd_http.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anybody have any idea why I get these permission messages and how I can fix this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;BR /&gt;Mark&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 09:31:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-App-for-Infrastructure-You-do-not-have-permissions-to/m-p/503886#M1869</guid>
      <dc:creator>markalbers</dc:creator>
      <dc:date>2020-06-11T09:31:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure: You do not have permissions to access objects of user</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-App-for-Infrastructure-You-do-not-have-permissions-to/m-p/505938#M2166</link>
      <description>&lt;P&gt;Nobody has a clue?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2020 11:00:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-App-for-Infrastructure-You-do-not-have-permissions-to/m-p/505938#M2166</guid>
      <dc:creator>markalbers</dc:creator>
      <dc:date>2020-06-24T11:00:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure: You do not have permissions to access objects of user</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-App-for-Infrastructure-You-do-not-have-permissions-to/m-p/506080#M2192</link>
      <description>&lt;P&gt;Do you have the roles granted to your user? There are new roles created by the Splunk app for Infrastructure app..&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 02:31:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-App-for-Infrastructure-You-do-not-have-permissions-to/m-p/506080#M2192</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2020-06-25T02:31:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure: You do not have permissions to access objects of user</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-App-for-Infrastructure-You-do-not-have-permissions-to/m-p/506104#M2197</link>
      <description>&lt;P&gt;Hm, maybe these roles have not been created... I only see these and to me they seem the regular ones, except for aws_admin, sales and victor_ops.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="roles.PNG" style="width: 392px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9342i92972D06C519B21A/image-size/large?v=v2&amp;amp;px=999" role="button" title="roles.PNG" alt="roles.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 06:57:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-App-for-Infrastructure-You-do-not-have-permissions-to/m-p/506104#M2197</guid>
      <dc:creator>markalbers</dc:creator>
      <dc:date>2020-06-25T06:57:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure: You do not have permissions to access objects of user</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-App-for-Infrastructure-You-do-not-have-permissions-to/m-p/506127#M2201</link>
      <description>&lt;P&gt;My apologies I'm getting my apps confused, no new roles exist for this app!&lt;/P&gt;&lt;P&gt;So the only thing I can think of is:&lt;BR /&gt;Is there any local files that override the default app settings?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i.e. in $SPLUNK_HOME/etc/apps/splunk_app_infrastructure/local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there anything that would override the default settings? And which Splunk version? I just tested in 7.3.3 and SAI 2.0.3&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 09:38:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-App-for-Infrastructure-You-do-not-have-permissions-to/m-p/506127#M2201</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2020-06-25T09:38:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure: You do not have permissions to access objects of user</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-App-for-Infrastructure-You-do-not-have-permissions-to/m-p/506143#M2206</link>
      <description>&lt;P&gt;No worries. I did not change anything in the configuration files of the SAI. When you test it, did you use the Splunk plugin for contentd or the &lt;SPAN&gt;http_write&amp;nbsp;plugin?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT size="4"&gt;Splunk App for Infrastructure&amp;nbsp;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT size="4"&gt;Version&lt;/FONT&gt; &lt;FONT size="4"&gt;2.1.0&lt;/FONT&gt; &lt;FONT size="4"&gt;Build&lt;/FONT&gt; &lt;FONT size="4"&gt;20&lt;/FONT&gt;&lt;/P&gt;&lt;DIV class="sc-bIqbHp dXQczz"&gt;&lt;FONT size="4"&gt;&lt;STRONG&gt;Splunk Enterprise&lt;/STRONG&gt; Version&lt;/FONT&gt; &lt;FONT size="4"&gt;8.0.3&lt;/FONT&gt; &lt;FONT size="4"&gt;Build&lt;/FONT&gt; &lt;FONT size="4"&gt;a6754d8441bf&lt;/FONT&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 25 Jun 2020 12:54:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-App-for-Infrastructure-You-do-not-have-permissions-to/m-p/506143#M2206</guid>
      <dc:creator>markalbers</dc:creator>
      <dc:date>2020-06-25T12:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure: You do not have permissions to access objects of user</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-App-for-Infrastructure-You-do-not-have-permissions-to/m-p/506251#M2234</link>
      <description>&lt;P&gt;I have not tried 2.1.0, only the older 2.0.x, we used the collectd standard install with minimal changes...&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2020 05:53:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-App-for-Infrastructure-You-do-not-have-permissions-to/m-p/506251#M2234</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2020-06-26T05:53:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure: You do not have permissions to access objects of user</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-App-for-Infrastructure-You-do-not-have-permissions-to/m-p/506260#M2236</link>
      <description>&lt;P&gt;Also in combination with CentOS? If so, which version? Because in my case the Splunk collectd plugin reports it cannot resolve the hostname, even when it is just a regular IP and the SplunkForwarder can send log events to our Splunk.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2020 07:07:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-App-for-Infrastructure-You-do-not-have-permissions-to/m-p/506260#M2236</guid>
      <dc:creator>markalbers</dc:creator>
      <dc:date>2020-06-26T07:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure: You do not have permissions to access objects of user</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-App-for-Infrastructure-You-do-not-have-permissions-to/m-p/506273#M2239</link>
      <description>&lt;P&gt;I believe it is an older Redhat 7.x&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2020 10:32:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-App-for-Infrastructure-You-do-not-have-permissions-to/m-p/506273#M2239</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2020-06-26T10:32:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure: You do not have permissions to access objects of user</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-App-for-Infrastructure-You-do-not-have-permissions-to/m-p/507571#M2446</link>
      <description>&lt;P&gt;Interesting, because I am trying to deploy it on a CentOS 7.6 &amp;amp; 7.4 version, so it should not differ much from that perspective.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you maybe have your deploy/installation commands?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 14:18:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-App-for-Infrastructure-You-do-not-have-permissions-to/m-p/507571#M2446</guid>
      <dc:creator>markalbers</dc:creator>
      <dc:date>2020-07-06T14:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure: You do not have permissions to access objects of user</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-App-for-Infrastructure-You-do-not-have-permissions-to/m-p/507714#M2455</link>
      <description>&lt;P&gt;Sorry I did not keep them! They were mostly defaults with minor changes to what the SAI app provided, note that this was all in app 2.0.x not 2.1.x, I have not tested the newest version yet...&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 00:49:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-App-for-Infrastructure-You-do-not-have-permissions-to/m-p/507714#M2455</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2020-07-07T00:49:59Z</dc:date>
    </item>
  </channel>
</rss>

