Splunk Enterprise

Permissions issue for user's reports.

Abass42
Communicator

I have a user that requested me to look into some of his reports. He wanted the permission of report 2 to match with report 1. Both are owned by two different people, but two people with similar roles and access. 

 After we tweaked the settings for the report, being shared in the app, having read access by all, and write permissions to those with the appropriate roles, they are still having issues viewing and editing. 

 

The owner of report 1 is the owner/creator of the report. The report runs as owner, and is shared globally. He doesn't have permissions to edit the actual alert. 

Abass42_0-1698182689505.png

He created the report initially, how come he cant edit it. I even cloned it and reassigned ownership, to no avail. 

Report 1  runs as owner, while report 2 has the option to run as owner or as the user. How come one report has that option while the other one is locked to running as owner?

As far as user two goes, his roles include permissions to the used indexes, as well as access to the app, default search app, and he has even more roles and permissions than user 1. Yet, he receives an error when trying to view the link that splunk sends out that has the attached report. 

Abass42_1-1698182905656.png

My question is, is there anywhere else I should be looking at in order to find permission discrepancies. From everything ive seen, both users have access to the required indexes, have pretty much soft-admin on splunk, and i assume they have viewed these in the past. From roles to users to capabilities, they have everything in order, or at least it seems. Is there something I should check in the configs? 

 

Thanks for any guidance. 

Labels (3)
Tags (2)
0 Karma

gurlest
Path Finder

Were you able to get this resolved?  We are seeing the same issue with some of our users after upgrade to v9.1.2.

 

Thanks!

Abass42
Communicator

Hey, thank you for your answer. Unfortunately, I have forgotten what exactly this was referring to, but I think i got it sorted out, as i havnt heard anything else about it. Not sure what the fix was. 

 

Thank you nonetheless. 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...