All Apps and Add-ons

Qualys Technical Add-On Setup Page Not Loading on Inputs Data Manager.

JoeAdkins
Observer

We use the Qualys Technical Add-On to pull vulnerability data into Splunk. We run it on our Inputs Data Manager We'd like to include additional fields in our data pulls, but in order to do that we need to go to the setup page. When going to the setup page on the IDM it never loads and we see this data in web_service.log

2024-09-03 21:26:32,726 INFO  __init__:654 - Authorization Failed: b'{"messages":[{"type":"ERROR","text":"You (user=myusername) do not have permission to perform this operation (requires capability: edit_telemetry_settings)."}]}'

From what I've been told edit_telemetry_settings can only be assigned to admins, not sc_admins. So no one has access to get to the setup page. 

Qualys is telling me that they have others users with IDMs that are using the Qualys TA fine, but our issue has persisted across restarts, multiple environments and multiple TA versions.

Can anyone confirm they can load the setup for the Qualys TA page from an IDM?

JoeAdkins_1-1725401296230.png

 

 

Labels (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...