#Random
This is a place to discuss all things outside of Splunk, its products, and its use cases.

Why am I getting the error "You do not have the capability to add data. Please contact your administrator" when I try to add data?

jclark4
New Member

This is a new install. I am trying to add new data and getting an error message:

"You do not have the capability to add data. Please contact your administrator"

This was installed from my Unix team, under the root user. I am assigned another account with full rights on the server.

Is there something that I am missing to be able to get this to work?

Thank you

Tags (1)
0 Karma

jgedeon120
Contributor

I was having this same issue. My issue was resolved by having an index that was not disabled on the host since it was an intermediate forwarder.

muebel
SplunkTrust
SplunkTrust

Hi jclark4, you'll need to make sure that you have administrative capabilities in the context of the Splunk instance you are trying to modify. Check out the admin manual for more info on this. Essentially, you'll want to make sure that your Splunk account is in the admin role. http://docs.splunk.com/Documentation/Splunk/6.0.2/Admin/Aboutusersandroles

Otherwise, you can directly edit the filesystem, modifying inputs.conf as desired to setup file monitor, scripted inputs or whatever config you want to get the data in.

Please let me know if this helps!

jclark4
New Member

My account is in the admin role, but i still get that message

0 Karma

nromito_splunk
Splunk Employee
Splunk Employee

Run splunk btool authorize list to check that the role you have still has the capabilities associated with adding data (edit_input_defaults, edit_monitor, indexes_edit, list_inputs, etc) Perhaps someone messed around with the capabilities given to default roles.

0 Karma

jclark4
New Member

I've verified this, it looks correct:

edit_input_defaults = enabled
edit_monitor = enabled
indexes_edit = enabled
list_inputs = enabled

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...