Security

Why can't I get a role to query _internal?

verbal_666
Builder

It's making me crazy!!! 😡😡😡😡😡

Splunk Enterprise 8.2.6, Cluster SH with 3 members.

 

 

[role_test]
cumulativeRTSrchJobsQuota = 0
cumulativeSrchJobsQuota = 0
grantableRoles = test
importRoles = user
srchIndexesAllowed = *;_*
srchMaxTime = 8640000

 

 

A "test" new Role. Import capabilities from "user" Role. A new user is assigner to the "test" Role.

1.JPG

 

2.JPG

 

3.JPG

 

No way to query _internal indexes!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! 😤😤😤

Any suggestion??? 🤔

Thanks.

Labels (1)
0 Karma

verbal_666
Builder

Solved with a SH Cluster members full restart... gosh!!! Strage to me... ... ... 🤔

Maybe Cluster was not correcly in sync... 🙄

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...