We have set the appropriate role and permissions on SA-ThreatInigence (write access) to enable ess_admin users to create suppressions. However, we keep getting this error:
"Failed to save suppression: Unexpected error "" from python handler: "[HTTP 403] Client is not authorized to perform requested action; https://127.0.0.1:8089/servicesNS/nobody/SA-ThreatIntelligence/saved/eventtypes". See splunkd.log for more details."
We do see the attempt to access in the splunkd_access data. Full Enterprise Admins can perform the suppression, but no ESS Admins. Is there a comprehensive list of permissions required? Do setting app permissions require a restart of splunk?