All Apps and Add-ons

Why am I receiving insufficient rights error when trying to create incident in ServiceNow?

maweber65
New Member

Hello,

When trying to create an alert in ServiceNow, the following error is received:

2018-02-05 17:45:04,143 ERROR pid=3047 tid=MainThread file=snow_ticket.py:_get_resp_record:256 | Failed with error: Insufficient rights to insert a x_splu2_splunk_ser_u_splunk_incident record

Thanks in advance,

Mark

0 Karma

maweber65
New Member

The logging level was turned up on the Splunk side. The error message now reads:

The admin role was added to the Splunk user and the level of logging was turned up on the Splunk side. The error now reads:

2018-02-05 20:43:05,021 ERROR pid=30182 tid=MainThread file=snow_ticket.py:_get_resp_record:256 | Failed with error: Insufficient rights to insert a x_splu2_splunk_ser_u_splunk_incident record

Since this occurred with the admin role, there must be something happening with the integration itself. Any ideas?

0 Karma

maweber65
New Member

After adding the admin role to the Splunk user, the logging level was turned up on the Splunk side. The error message now reads:

2018-02-05 20:43:05,021 ERROR pid=30182 tid=MainThread file=snow_ticket.py:_get_resp_record:256 | Failed with error: Insufficient rights to insert a x_splu2_splunk_ser_u_splunk_incident record

Since this occurred with the admin role, there must be something happening with the integration itself. Any ideas?

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...