Knowledge Management

What causes this scheduler failure? "Error in 'summaryindex' command: Permission denied to index 'summary'."?

twinspop
Influencer
06-08-2016 21:11:02.773 -0400 ERROR SavedSplunker - savedsearch_id="UserX;search;ss_index_delay_times", message="Error in 'summaryindex' command: Permission denied to index 'summary'.". No actions executed

The search is owned by UserX, and scheduled to run as 'owner'. UserX has plenty other searches that are running and saving to this same summary index. This very search runs perfectly fine most of the time. UserX is admin level.

It's running on a solo search head talking to 3 indexers. Index summary is defined on the SH, but the SH is set to forward to the indexers. No local indexing. Linux, running 64-bit 6.4.1.

0 Karma

haliakbar_splun
Splunk Employee
Splunk Employee

Can you confirm that the summary search is running is using the # enable summary indexing
action.summary_index = 1 or is the search using the search collect command? Can you paste the search if possible?

0 Karma

twinspop
Influencer

Confirmed, yes. The box is checked.

A sample search, very simple:

error | stats count by host

but it hasn't happened since June 10th, a day we pruned lots of the per minute searches we had. Could it be related to overrun quotas? If so, strange message.

0 Karma
Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...