Splunk Dev

why does loadjob fail producing the message: Error in 'SearchOperator:loadjob': error accessing https xxxx statusCode=403, description=Forbidden

rphillips_splk
Splunk Employee
Splunk Employee

loadjob returning statusCode=403, description=Forbidden when a user without admin role calls a search artifact created by a user with admin role. This works with 6.3.4. but in 6.3.5 produces the following error:

Error in 'SearchOperator:loadjob': error accessing https://127.0.0.1:8089/servicesNS/some-admin/search//saved/searches/mysearchtest/?output_mode=json, statusCode=403, description=Forbidden

Tags (1)
0 Karma

rphillips_splk
Splunk Employee
Splunk Employee

This is a known bug (SPL-123305) in 6.3.5 which is fixed in 6.3.6 and 6.4.2

as a workaround you can call the search artifact by using the 'nobody' user like:
| loadjob savedsearch="nobody:search:mysearchtest"

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...