Splunk Enterprise

Permissions issue for user's reports.

Abass42
Path Finder

I have a user that requested me to look into some of his reports. He wanted the permission of report 2 to match with report 1. Both are owned by two different people, but two people with similar roles and access. 

 After we tweaked the settings for the report, being shared in the app, having read access by all, and write permissions to those with the appropriate roles, they are still having issues viewing and editing. 

 

The owner of report 1 is the owner/creator of the report. The report runs as owner, and is shared globally. He doesn't have permissions to edit the actual alert. 

Abass42_0-1698182689505.png

He created the report initially, how come he cant edit it. I even cloned it and reassigned ownership, to no avail. 

Report 1  runs as owner, while report 2 has the option to run as owner or as the user. How come one report has that option while the other one is locked to running as owner?

As far as user two goes, his roles include permissions to the used indexes, as well as access to the app, default search app, and he has even more roles and permissions than user 1. Yet, he receives an error when trying to view the link that splunk sends out that has the attached report. 

Abass42_1-1698182905656.png

My question is, is there anywhere else I should be looking at in order to find permission discrepancies. From everything ive seen, both users have access to the required indexes, have pretty much soft-admin on splunk, and i assume they have viewed these in the past. From roles to users to capabilities, they have everything in order, or at least it seems. Is there something I should check in the configs? 

 

Thanks for any guidance. 

Labels (3)
Tags (2)
0 Karma

gurlest
Path Finder

Were you able to get this resolved?  We are seeing the same issue with some of our users after upgrade to v9.1.2.

 

Thanks!

Abass42
Path Finder

Hey, thank you for your answer. Unfortunately, I have forgotten what exactly this was referring to, but I think i got it sorted out, as i havnt heard anything else about it. Not sure what the fix was. 

 

Thank you nonetheless. 

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...