Security

Getting obscure error message: Splunk could not update permissions for resource admn/win-event-log collections Splunkd internal error

wmysplunk
New Member

New to splunk, testing things out but I've hit a wall...

I'm trying to do remote windows event log collection on a W2K3 SP2 box. It seems to be working fine and I'm picking up events and can do searches for things like account logon events, login failures, and such. No problem there. However those events are not showing up in the Windows Management application (nothing is showing up under System Management for any of the snapshot reports like "The Most Frequent Logons" or "Failed Logins by Host" or Failed Windows UPdates by Host", etc., etc...).

I assumed this was a problem with the permissions so I go to splunk>Manager>Data inputs >> Event log collections, select "Permissions" for the computer I am monitoring. Then I select "All apps" under the "Object should appear in" option. For kicks, I just give Everyone Read and Write, then hit Save. Splunk keeps coming back with "Splunk could not update permissions for resource admn/win-event-log collections Splunkd internal error".

I checked splunkd.log and observed corresponding entries for when I tried to save the new permissions; the entry is: "ERROR AdminManager - : This handler claims to support this action (4), but has not implemented it."

I'm getting the same thing even for localhost log event collection. I'd be very happy if anyone has an idea about this! Thanks in advance.

0 Karma

btruter
New Member

Sorry, i don't have an answer, but I do have the exact same error. My logs say the same as yours, also.

Windows 2008 R2 Server, Splunk version 4.1.4, build 82143

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...