Splunk Enterprise

Unable to Access on Splunk Enterprise

Roy_9
Motivator

Hello,

I have an issue where I was part of multiple roles on Splunk Enterprise and Splunk Enterprise Security, the same role and saml group has access to all the indexes, On the Splunk Enterprise i am part of 3 roles(A, B, C) which has search filters but I am already part of role D which has access to all indexes but when I am trying to search any data, I am not getting any data, But On Enterprise Security SH, I am able to view all the data as expected.

Is it something like precedence issue on Splunk Enterprise SH that is causing the issue?Please help me.

 

 

Thanks

0 Karma

marnall
Motivator

At first glance I would suspect that the search filters for your roles are contradicting each other and filtering out all events.

E.g. if you have the following roles with search filters:

ROLE A - (index=index1 sourcetype=something)

ROLE B - (index=index2 sourcetype=something)

Then if you have role A and B, then Splunk will force you to search with "(index=index1 sourcetype=something) (index=index2 sourcetype=something)" which will retrieve 0 events because none exist in both index1 and index2 at the same time.

Are you able to post your sanitized search filters to look for contradictory filters?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...