All Apps and Add-ons

Cloud Splunk Add-on for Unix and Linux addon configure failing due to not having edit_monitor and edit_scripted

janakap
Engager

Hi, 

I installed Splunk Add-on for Unix and Linux addon in Splunk Cloud. During the initial configuration of the add-on it gives the error "There was an unexpected problem while saving the inputs. Please reload the page and try again." when trying to save the configuration.

Looking at the http request errors I found that not having edit_monitor and edit_scripted permissions seems to be the problem 

example error: [SPLUNKD] You (user=sc_admin) do not have permission to perform this operation (requires capability: edit_scripted).

In the user and role permission settings,  I didn't find these permissions to be set to the related role. 

Appreciate any help to solve the issue or any workarounds. 

Thanks,

Janaka

Labels (1)
Tags (2)

VatsalJagani
SplunkTrust
SplunkTrust

@janakap , @figmentbritton  - That could be due to you trying to create/enable input which is generally not allowed on Splunk cloud SH and Indexers.

You can create input in the cloud IDM (Input Data Manager) instance only. - https://www.splunk.com/en_us/blog/platform/introducing-inputs-data-manager-on-splunk-cloud.html?loca... 

--------------
I hope this helps!!!

0 Karma

figmentbritton
Engager

I'm having the same issue - is it possible to enable these permissions in Splunk Cloud?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...