Security

When uploading a data file, why is the progress bar getting stuck at 100% for a non-admin user?

khagan
Path Finder

Hi,

I'm having an issue uploading files to Splunk as a particular user. When I attempt the upload process, the progress bar hangs at 100% and never completes, and searching confirms that the data has not been added. No error is logged.

This only occurs when attempting to add it as my custom role. This role inherits the default "user" capabilities, and also has the "edit_monitor" and "indexes_edit" capabilities.

Uploading the same file as an admin does not have this issue, and the upload completes instantly. Is there a capability missing that might be causing this?

1 Solution

khagan
Path Finder

Found the answer to this: the user needs to have the "edit_tcp" capability. I'm not sure why that's required to upload a file, but granting it to the user solved the problem.

View solution in original post

khagan
Path Finder

Found the answer to this: the user needs to have the "edit_tcp" capability. I'm not sure why that's required to upload a file, but granting it to the user solved the problem.

Roy_9
Motivator

Worked for me. Thank you

0 Karma

ChrisG
Splunk Employee
Splunk Employee

I have seen this where you exceed the disk space limit in server.conf (SPL-109362), is there any difference in this setting between your two users?

0 Karma

khagan
Path Finder

How can this value be set differently for different users? I was under the impression the setting in server.conf was a global setting.

0 Karma

yannK
Splunk Employee
Splunk Employee

What version are you on ?

0 Karma

khagan
Path Finder

I'm on version 6.2.5

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...