Security

Why can only admin level users run the iplocation command when this wasn't an issue before?

sjohnnehta
Path Finder

For some reason, users with less than admin privileges in Splunk can no longer run iplocation based searches or see dashboard panels with that contained. They were able to, so not sure what I've done. Anyway, I'm not sure where else to check permissions for this internal Splunk function and I'm not clear which troubleshooting steps (btool or whatever) to do next to identify the issue. Iplocation based searches and dashboards work fine for admin level users, so the functionality is there. If I elevate a standard user to admin, it then starts working for them too. Thought I'd try here before opening a case.

Thanks.

Tags (2)
0 Karma
1 Solution

sjohnnehta
Path Finder

The reason this happened was because it relied on a field extraction that the users didn't have permissions for. I fixed that up and all good.

View solution in original post

0 Karma

sjohnnehta
Path Finder

The reason this happened was because it relied on a field extraction that the users didn't have permissions for. I fixed that up and all good.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...