Security

Why can't I get a role to query _internal?

verbal_666
Builder

It's making me crazy!!! 😡😡😡😡😡

Splunk Enterprise 8.2.6, Cluster SH with 3 members.

 

 

[role_test]
cumulativeRTSrchJobsQuota = 0
cumulativeSrchJobsQuota = 0
grantableRoles = test
importRoles = user
srchIndexesAllowed = *;_*
srchMaxTime = 8640000

 

 

A "test" new Role. Import capabilities from "user" Role. A new user is assigner to the "test" Role.

1.JPG

 

2.JPG

 

3.JPG

 

No way to query _internal indexes!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! 😤😤😤

Any suggestion??? 🤔

Thanks.

Labels (1)
0 Karma

verbal_666
Builder

Solved with a SH Cluster members full restart... gosh!!! Strage to me... ... ... 🤔

Maybe Cluster was not correcly in sync... 🙄

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...