Security

Splunk Manager Admin Permission Problem

harald_leitl
Path Finder

Hi,

Just updated my search heads to 4.3 and now I get following message when trying to create new roles in Splunk manager.

There was an error retrieving the configuration, can not process this page.

You do not have permission to access the configuration for this page.

No difference between LDAP user (with admin privilege) and local Admin user, both receive the same error.

my /opt/splunk/etc/apps/search/metadata/default.meta shows:

....

*[manager/authentication_roles]

access = read : [ admin ], write : [ admin ]*

...

that should be okay.

Any suggestion?

thanks,

harry

Tags (1)
0 Karma

lguinn2
Legend

Sometimes I see errors like this if Splunk was started/stopped by root, when it normally runs as a different user. Some of the files become owned by root and then odd things don't work. In Linux, there is a simple fix. Assuming that

  • Splunk is installed in /opt/splunk
  • Splunk should run as user splunkit
  • you are signed in as a user with sudo privileges

    cd /opt
    sudo chown -R splunkit splunk

Of course, the problem could be something entirely different...

harald_leitl
Path Finder

any other suggestion? could it be a bug?

0 Karma

harald_leitl
Path Finder

just chanced permissions - unfortunately still the same behavior.

0 Karma
Get Updates on the Splunk Community!

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...

Stay Connected: Your Guide to October Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...