Getting Data In

vectra integration

aly347774
Loves-to-Learn Lots

when I go to search head to change configuration of TA_vectra_detect_json I find this (You do not have permissions to edit this configuration.) 

 

Labels (3)
0 Karma

aly347774
Loves-to-Learn Lots

When I go to SearchHead to edit, it tells me this message (You do not have permissions to edit this configuration)

0 Karma

Richfez
SplunkTrust
SplunkTrust

Yes.  IF you have a search head cluster (shc), AND you are trying to edit the config on one of the members instead of on the deployer, THEN that's exactly the message I expect you to get. 

It *might* be possible to get that if you simply don't have some permission or another that's required, but I think those messages are different ones.

So - Do you have a search head cluster?

If you don't know, then ask your Splunk folks and/or have them manage this config for you.

If you are the Splunk person and don't know what I'm saying (and you built it) then you don't have a SHC and we'll have to look into other things.

 

(Also, please be careful as to *which* "reply" button you click, so we can keep the threads going correctly instead of being willy-nilly all over the place!)

0 Karma

Richfez
SplunkTrust
SplunkTrust

That specific error is usually caused by you having a Search Head Cluster, then trying to edit configs on a Search Head Member instead of via the Deployer then deploying it.

See this for more information.

https://docs.splunk.com/Documentation/Splunk/9.2.0/DistSearch/PropagateSHCconfigurationchanges

If that does not seem to be the problem here, then reply back with a few more specifics!

 

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...