Splunk Enterprise Security

ESS Admin Role unable to create correlation searches

ehowardl3
Path Finder

I'm getting the following error while trying to save a correlation search as a user with the ess_admin role:

There was an error saving the correlation search: User 'local_ess_admin' with roles { ess_admin, ess_analyst, ess_user, local_ess_admin, power, user } cannot write: /nobody/SplunkEnterpriseSecuritySuite/savedsearches/Threat - test2 - Rule { read : [ * ], write : [ admin ] }, export: global, owner: admin, removable: no, modtime: 1591818982.977029000

The ess_admin role should by default be allowed to edit correlation searches, and the role does have the "edit_correlationsearches" capability. Is there any other capability that should be enabled in order for this to work?

 

0 Karma

The_Simko
Path Finder

Is this an isolated issue? It makes me wonder if something weird like starting Splunk with the wrong user isn't hitting here.
If you create a new user as an admin (give them the full admin role, not just ess admin). Can they create a correlation search? If so, go back to the account you have issues with and assign them admin, not just ess_admin.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...