Hi splunkers,
I've defined a new role and check all capabilities for that but just access to a specific index. when i search in that index, it doesn't show any results for me. With another user and another role i can search in that index. Something wired is when i change the user role to for example "user", the search results shown. is there a limit in number of roles can be defined in splunk? How can i troubleshoot these kindes of permissions in splunk logs?
Thanks for your answer
all capabilities for that role are checked and in "indexes" section, cisco-asa, cisco-devices, cisco-ise, dhcp, fortigate and waf are checked. Here is a picture of authorize.conf:
And which index is the one you're trying to access and can't?
All of indexes listed above
The number of roles defined is not the issue. Either the role or the user is defined incorrectly. Please share the settings for the role, in particular the "indexes" tab.