Security

searches skipped in the last 24hours. 500 internal server error. insufficient permission to access this resource

mfonisso
Explorer

when i try running a search on my Splunk enterprise in the search and reporting app i get the "insufficient permission to access this resource" message.  i tried to click on  the things under settings and i get the "500 internal server error" message and there's this severe warning message in my search scheduler that says "searches skipped in the last 24 hours"
how do i troubleshoot these and get my splunk enterprise running normally again?

Labels (1)
0 Karma
1 Solution

mfonisso
Explorer

I've been able to resolve the issues. I made some changes to the configuration files and everything is working perfectly ok now

View solution in original post

0 Karma

mfonisso
Explorer

I've been able to resolve the issues. I made some changes to the configuration files and everything is working perfectly ok now

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @mfonisso,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @mfonisso,

what are the resources of your Splunk server?

Splunk requires at least 12 CPUs and 12 GB RAM (more if you have ES or ITSI) and a disk with at least 800 IOPS.

Ciao.

Giuseppe

0 Karma

mfonisso
Explorer

how do I check my resources, please? although up until 2 days ago my Splunk has been operating well

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...