Splunk Enterprise Security

Splunk Enterprise Security: Why am I receiving "Search could not be updated: [HTTP 500]" error when trying to save correlation search as ess_admin?

droth333
Explorer

In Splunk Enterprise Security (ES), we cannot save a correlation search as a user with ess_admin. This works if user is admin.

The navigation is: ES/Configure/Content Management/Create new Content/Correlation Search//Save

The full error is displayed in error bar in the UI:

Search could not be updated: [HTTP 500] Splunkd internal error; [{'type': 'ERROR', 'code': None, 'text': 'Unexpected error "" from python handler: "[HTTP 403] Client is not authorized to perform requested action; https://127.0.0.1:8089/servicesNS/nobody/SA-ThreatIntelligence/storage/collections/data/correlations.... See splunkd.log for more details.'}]

There is not much more in splunkd.log

Is "configuration" change actually a literal "admin" function?
We want to make all "users" of ES to be at most ess_admin.

Thanks,
Dave

0 Karma
1 Solution

smoir_splunk
Splunk Employee
Splunk Employee

You cannot assign ess_admin to users. " You must use a Splunk platform admin role to administer an Enterprise Security installation." See http://docs.splunk.com/Documentation/ES/4.5.1/Install/ConfigureUsersRoles#Configuring_user_roles

If you want ess_analyst users to be able to edit correlation searches, grant them that capability on the ES Permissions page. See http://docs.splunk.com/Documentation/ES/4.5.1/Install/ConfigureUsersRoles#Add_capabilities_to_a_role

View solution in original post

smoir_splunk
Splunk Employee
Splunk Employee

You cannot assign ess_admin to users. " You must use a Splunk platform admin role to administer an Enterprise Security installation." See http://docs.splunk.com/Documentation/ES/4.5.1/Install/ConfigureUsersRoles#Configuring_user_roles

If you want ess_analyst users to be able to edit correlation searches, grant them that capability on the ES Permissions page. See http://docs.splunk.com/Documentation/ES/4.5.1/Install/ConfigureUsersRoles#Add_capabilities_to_a_role

droth333
Explorer

Thanks smoir! Much much more clear now! Also for thanks for quick response.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...