Security

Minimal user capabilities for generating PDF email report?

gljiva
Path Finder

Hi, I've noticed that I have to add admin_all_object to be able to receive PDF report. If i remove that capability I get

"An error occurred while generating a PDF of this report: Failed to contact appserver at https://server:8000/en-US/report/: HTTP Error 500: Internal Server Error"

Problem is that I would like to give users as little privileges as possible, and when I enable all capabilities that I managed to isolate for proper PDF reporting, users can change apps and some other stuff. Is there a way to check what are minimal capabilities necessary for some action to work (like PDF reporting)? Is there some other workaround for enabling users to add PDF reports but minimize their capabilities?

thx

Tags (3)
1 Solution

Genti
Splunk Employee
Splunk Employee

currently PDF sent through emails can only be done by the admin user. This should change in the next few releases.

View solution in original post

rtclark
Explorer

This was fixed in 4.1.6:

"PDF printing is limited to only the admin user. (SPL-33953)"

http://www.splunk.com/base/Documentation/latest/ReleaseNotes/4.1.6

I just got back to troubleshooting this issue in my environment, and to my surprise the 500 error was no longer reproducible. I found this question and went searching to make sure that this was indeed the magic that had fixed the issue.

-rtc

Genti
Splunk Employee
Splunk Employee

currently PDF sent through emails can only be done by the admin user. This should change in the next few releases.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...