<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Setting up permissions for viewing alerts? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Setting-up-permissions-for-viewing-alerts/m-p/233960#M4365</link>
    <description>&lt;P&gt;Thanks, but the concerned user's role has even write permissions (I've found this is a possible solution at a different question) for those objects.&lt;/P&gt;</description>
    <pubDate>Wed, 20 Jan 2016 09:39:40 GMT</pubDate>
    <dc:creator>szabados</dc:creator>
    <dc:date>2016-01-20T09:39:40Z</dc:date>
    <item>
      <title>Setting up permissions for viewing alerts?</title>
      <link>https://community.splunk.com/t5/Alerting/Setting-up-permissions-for-viewing-alerts/m-p/233956#M4361</link>
      <description>&lt;P&gt;Users within my environment, who have the Power user role in Splunk, can't access the results of the alert, they are getting "The view you requested could not be found." error message all the time. They have the "schedule_search" capability which I believe is the needed on for this. No matter, they try to open the link from the alert email, or from the web gui from the triggered alerts list.&lt;BR /&gt;
Edit:&lt;BR /&gt;
I checked in the audit.log, the only capability the user was denied is the "edit_user".&lt;BR /&gt;
I granted this capability to the user's role, but still can't see the alert, however, the denied-lines disappeared from the log.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:26:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Setting-up-permissions-for-viewing-alerts/m-p/233956#M4361</guid>
      <dc:creator>szabados</dc:creator>
      <dc:date>2020-09-29T08:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up permissions for viewing alerts?</title>
      <link>https://community.splunk.com/t5/Alerting/Setting-up-permissions-for-viewing-alerts/m-p/233957#M4362</link>
      <description>&lt;P&gt;If you see the URL which is will launched on the click of "View results in Splunk", it points to a search result in the dispatch directory. Which may have expired/removed from dispatch directory, depending upon the search job expiration. If the job is expired, you'll get that error, even as admin.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 17:01:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Setting-up-permissions-for-viewing-alerts/m-p/233957#M4362</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-01-15T17:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up permissions for viewing alerts?</title>
      <link>https://community.splunk.com/t5/Alerting/Setting-up-permissions-for-viewing-alerts/m-p/233958#M4363</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm afraid this is not the case. If there is a triggered alert, I can access it as an administrator, but not with a power user. The job can't be expired, because it was run like 1 minute ago, and also visible as admin.&lt;BR /&gt;
Edit:&lt;BR /&gt;
If I create an alert with a power user, that user can see it's own alert.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2016 16:29:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Setting-up-permissions-for-viewing-alerts/m-p/233958#M4363</guid>
      <dc:creator>szabados</dc:creator>
      <dc:date>2016-01-19T16:29:17Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up permissions for viewing alerts?</title>
      <link>https://community.splunk.com/t5/Alerting/Setting-up-permissions-for-viewing-alerts/m-p/233959#M4364</link>
      <description>&lt;P&gt;Hi @szabados,&lt;BR /&gt;
As a start, you could review the alert and alert action permissions that are set currently for this alert. Alerts and alert actions are knowledge objects with their own permissions. Here is some documentation:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.1511/Alert/AlertPermissions"&gt;http://docs.splunk.com/Documentation/Splunk/6.3.1511/Alert/AlertPermissions&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2016 18:44:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Setting-up-permissions-for-viewing-alerts/m-p/233959#M4364</guid>
      <dc:creator>frobinson_splun</dc:creator>
      <dc:date>2016-01-19T18:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up permissions for viewing alerts?</title>
      <link>https://community.splunk.com/t5/Alerting/Setting-up-permissions-for-viewing-alerts/m-p/233960#M4365</link>
      <description>&lt;P&gt;Thanks, but the concerned user's role has even write permissions (I've found this is a possible solution at a different question) for those objects.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2016 09:39:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Setting-up-permissions-for-viewing-alerts/m-p/233960#M4365</guid>
      <dc:creator>szabados</dc:creator>
      <dc:date>2016-01-20T09:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up permissions for viewing alerts?</title>
      <link>https://community.splunk.com/t5/Alerting/Setting-up-permissions-for-viewing-alerts/m-p/233961#M4366</link>
      <description>&lt;P&gt;I'm having the exact same issue.  The user is able to execute the alert search directly from the search bar, however when they attempt to open the "View Results" link in the alert email, it tells them, "The view you requested could not be found." As an administrative user, I am able to open the email link without issue, but a user or power user is unable to open the link. &lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2016 20:44:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Setting-up-permissions-for-viewing-alerts/m-p/233961#M4366</guid>
      <dc:creator>mgranger1</dc:creator>
      <dc:date>2016-09-08T20:44:24Z</dc:date>
    </item>
  </channel>
</rss>

