Security

Access control for App acting strange

jravida
Communicator

Hi Folks,

I'll try to keep this short and coherent.

I created an app, a role with capabilities and indexes, added dashboards and panels (from another in-house app we made, but with tighter access control) set it all up (triple checked access control).

When I add "User" for an inherited role, it works. I can view all panels, I can drill down and search.

When I mirror the capabilities of the user, and apply them to my role, it works. Once. When I drill down I am met, in the browser, with the error: "Splunk cannot find the "search" view". In the web_services log, I find: "An unknown view name "search is referenced in the navigation definition for "vm_app".

If I then go back to the dashboard, 2 of my 6 panels are broken. One says "No results found" for a table, and the other says "N/A" for a single value panel. All other panels work and use the same indexes. 2 of the 3 that use a lookup table are broken, so I know it isn't access control on the lookup. This makes no sense, as the panels load correctly until I drill down, then the 2 break. This is repeatable.

0 Karma

jravida
Communicator

I found the issue. It wasn't the actual app permissions for 'search', it was the View permissions, Settings>>User Interface. The view for search was restricted by someone before, limited to like 3 apps. Once I gave read for the group it worked perfect!

DalJeanis
Legend

@jravida - I moved your comment on this old one to an answer, since you solved the problem and reported the solution. Please accept your answer to mark the question answered.

0 Karma

lguinn2
Legend

I would file a bug at http://www.splunk.com/support
This may be beyond the capabilities of the answer community.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...