<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I am getting mostly info=denied events for specific users while searching for _audit index. While user  can no longer query any indexes. Does that info indicates permission issues? or something else. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/I-am-getting-mostly-info-denied-events-for-specific-users-while/m-p/426498#M191089</link>
    <description>&lt;P&gt;I am getting info=denied events for specific users while searching for _audit index. What is the significance of this as users are not able to search any indexes? any leads. &lt;/P&gt;</description>
    <pubDate>Sat, 03 Aug 2019 00:25:39 GMT</pubDate>
    <dc:creator>pateriaak</dc:creator>
    <dc:date>2019-08-03T00:25:39Z</dc:date>
    <item>
      <title>I am getting mostly info=denied events for specific users while searching for _audit index. While user  can no longer query any indexes. Does that info indicates permission issues? or something else.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-am-getting-mostly-info-denied-events-for-specific-users-while/m-p/426498#M191089</link>
      <description>&lt;P&gt;I am getting info=denied events for specific users while searching for _audit index. What is the significance of this as users are not able to search any indexes? any leads. &lt;/P&gt;</description>
      <pubDate>Sat, 03 Aug 2019 00:25:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-am-getting-mostly-info-denied-events-for-specific-users-while/m-p/426498#M191089</guid>
      <dc:creator>pateriaak</dc:creator>
      <dc:date>2019-08-03T00:25:39Z</dc:date>
    </item>
    <item>
      <title>Re: I am getting mostly info=denied events for specific users while searching for _audit index. While user  can no longer query any indexes. Does that info indicates permission issues? or something else.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-am-getting-mostly-info-denied-events-for-specific-users-while/m-p/426499#M191090</link>
      <description>&lt;P&gt;hi @pateriaak - Are you trying to say that the users who are getting info=denied in the _audit index are not able to search all other indexes as well, and not just the _audit index?&lt;BR /&gt;
Most times splunk admins will restrict _audit access to most users as I won't want end users to see audit info.&lt;BR /&gt;
But for this what i do is go to accesss controls &amp;gt; roles and manually remove _audit index from the specified user roles.&lt;BR /&gt;
If the affected users in your case are not able to see/search any indexes I recommend that you navigate to one of the roles and check is that role has permission set for one of the indexes that they should have access to..&lt;/P&gt;</description>
      <pubDate>Sat, 03 Aug 2019 07:24:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-am-getting-mostly-info-denied-events-for-specific-users-while/m-p/426499#M191090</guid>
      <dc:creator>Sukisen1981</dc:creator>
      <dc:date>2019-08-03T07:24:01Z</dc:date>
    </item>
    <item>
      <title>Re: I am getting mostly info=denied events for specific users while searching for _audit index. While user  can no longer query any indexes. Does that info indicates permission issues? or something else.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-am-getting-mostly-info-denied-events-for-specific-users-while/m-p/426500#M191091</link>
      <description>&lt;P&gt;hi @Sukisen1981 I was unclear in my question about _audit index, I was seeing this info=denied in _audit index for a user as a splunk admin and yes later I was able to figure out access issues causing users not able to search any indexes. thank you for your comments and sorry about being unclear initially. &lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2019 15:41:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-am-getting-mostly-info-denied-events-for-specific-users-while/m-p/426500#M191091</guid>
      <dc:creator>pateriaak</dc:creator>
      <dc:date>2019-08-05T15:41:05Z</dc:date>
    </item>
    <item>
      <title>Re: I am getting mostly info=denied events for specific users while searching for _audit index. While user  can no longer query any indexes. Does that info indicates permission issues? or something else.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-am-getting-mostly-info-denied-events-for-specific-users-while/m-p/426501#M191092</link>
      <description>&lt;P&gt;hi @pateriaak - Glad that you figured out the issue, had to be an index permission issue.&lt;BR /&gt;
Please accept my answer if it helps similar issue resolution in a significant way or please post your answer if you did something very different to resolve the issue , for the benefit of the forum&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2019 16:07:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-am-getting-mostly-info-denied-events-for-specific-users-while/m-p/426501#M191092</guid>
      <dc:creator>Sukisen1981</dc:creator>
      <dc:date>2019-08-05T16:07:07Z</dc:date>
    </item>
  </channel>
</rss>

