Getting Data In

Posting to a receiver using REST API giving "insufficient permission to access this resource" error

bengwall
New Member

We are investigating how to create a Splunk log entry over the REST API via JavaScript. I'm posting the following event via the REST API:

curl -k -u user:password "https://tspl001:8089/services/receivers/simple?source=www&sourcetype=junk&index=angularjs_test" -d "2015-01-23 12:45:03 CST Hello there"

Here is the response:

<?xml version="1.0" encoding="UTF-8"?>
<response>
  <messages>
    <msg type="WARN">insufficient permission to access this resource</msg>
  </messages>
</response>

I was told that my user has write privileges and that I'm using the correct sourcetype and index values. I cannot file any reference to what the "www" source is.

0 Karma
1 Solution

kbarker302
Communicator

Please see the answer posted here:

https://answers.splunk.com/answers/75013/minimum-permissions-required-for-using-http-simple-receiver...

Apparently there is an edit_tcp capability that needs to be defined in authorize.conf for the simple receiver to work:

http://docs.splunk.com/Documentation/Splunk/6.3.2/admin/Authorizeconf

Fyi, the [capability::edit_tcp] stanza was already present in my system/default/authorize.conf file. I took it out just to see if I could reproduce your problem, but I was still able to execute the REST calls.

View solution in original post

kbarker302
Communicator

Please see the answer posted here:

https://answers.splunk.com/answers/75013/minimum-permissions-required-for-using-http-simple-receiver...

Apparently there is an edit_tcp capability that needs to be defined in authorize.conf for the simple receiver to work:

http://docs.splunk.com/Documentation/Splunk/6.3.2/admin/Authorizeconf

Fyi, the [capability::edit_tcp] stanza was already present in my system/default/authorize.conf file. I took it out just to see if I could reproduce your problem, but I was still able to execute the REST calls.

bengwall
New Member

Assigning the edit_tcp attribute solved the issue. Thanks.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...