Security

Possible bug with changing permission on source based field extraction

knielsen
Contributor

Hello,

I just ran into the issue that I couldn't change the permission of a source based field extraction via GUI on 7.3.1.

This only happens for source based field extrations, sourcetype ones are not affected.

Clicking on the "Permissions" Link in Sharing results in an error like this:

Splunk could not retrieve permissions for resource data/props/extractions [HTTP 404] https://127.0.0.1:8089/servicesNS/kainiels/search/data/props/extractions/source%253A%253A%252Fvar%25...; [{'type': 'ERROR', 'text': 'Could not find object id=source%3A%3A/var/log/bar : EXTRACT-foo', 'code': None}]

Can someone confirm that issue, or is our installation maybe broken somehow? I didn't see this mentioned in the release notes of later versions...

Labels (1)

darius_diederic
Engager

I received word from developers this bug will be fixed on version 7.2.11, 7.3.6 and 8.0.4 with a release date of 05/12/2020.

dbot2001
Path Finder

Is there a workaround for this?

Tags (1)
0 Karma

kaurinko
Communicator

I can confirm, that this only happens for source based field extractions. Ones with sourcetype-based searches are not affected.

0 Karma

kaurinko
Communicator

I have the same problem with 8.0.1. Would be interested to know if there is a solution.

darius_diederic
Engager

I have the same problem with version 7.2.9.1. It appears to me that this error occurs for any field extraction that contains a forward slash /. Did happen to get any confirmation this is a bug?

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...