Security

Why can't I get a role to query _internal?

verbal_666
Builder

It's making me crazy!!! 😡😡😡😡😡

Splunk Enterprise 8.2.6, Cluster SH with 3 members.

 

 

[role_test]
cumulativeRTSrchJobsQuota = 0
cumulativeSrchJobsQuota = 0
grantableRoles = test
importRoles = user
srchIndexesAllowed = *;_*
srchMaxTime = 8640000

 

 

A "test" new Role. Import capabilities from "user" Role. A new user is assigner to the "test" Role.

1.JPG

 

2.JPG

 

3.JPG

 

No way to query _internal indexes!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! 😤😤😤

Any suggestion??? 🤔

Thanks.

Labels (1)
0 Karma

verbal_666
Builder

Solved with a SH Cluster members full restart... gosh!!! Strage to me... ... ... 🤔

Maybe Cluster was not correcly in sync... 🙄

0 Karma
Get Updates on the Splunk Community!

Index This | What did the zero say to the eight?

June 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

Splunk Observability Cloud's AI Assistant in Action Series: Onboarding New Hires & ...

This is the fifth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Now Playing: Splunk Education Summer Learning Premieres

It’s premiere season, and Splunk Education is rolling out new releases you won’t want to miss. Whether you’re ...