All Apps and Add-ons

Slack Notification Alert: Seem to require admin privlidges to send alert per event

sharkannon
Explorer

Since upgrading to splunk 7.2.0 (we were on 7.0.0 before), Alerts that were created by non admin users that use the "For each result" trigger for alerts don't seem to go through with the splunk plugin.

We tried attaching both the slack alert and the email alerts, and users receive the emails correctly, but the slack alerts "disappear". I can assign the alert to a user with Admin OR promote the user to Admin and the alert seems to start working fine.

Do you know what permissions I may need to update our users with, or if this is a bug in the app?

The only thing I can see that MAY coincide is an error that says:

Error in 'sendalert' command: sendmodalert: Cannot access results_file: '/opt/splunk/var/run/splunk/dispatch/scheduler__USER__search__testalert_at_1541565840_19/per_result_alert/tmp_5.csv.gz'. Permission denied.

Other than that I can't seem to find anything in the logs that may be associated. File permissions and everything are correct.

serialmonkey
Path Finder

For those wondering, this was introduced in 7.2.1 and is apparently resolved in 7.2.4

See https://docs.splunk.com/Documentation/Splunk/7.2.3/ReleaseNotes/Knownissues - SPL-163315 & SPL-163882

paimonsoror
Builder

Any update on this? We are running into the same issue with 7.2.1. This is a serious issue if users need the AAO capability to do this.

0 Karma

sharkannon
Explorer

Through trial and error, discovered that you need to add admin_all_objects permissions to all users that use this feature. This appears to be something fairly new and, IMO kinda dangerous.

richgalloway
SplunkTrust
SplunkTrust

If it used to work and now doesn't, you should file a support case.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...