Splunk Enterprise

Unable to Access on Splunk Enterprise

Roy_9
Motivator

Hello,

I have an issue where I was part of multiple roles on Splunk Enterprise and Splunk Enterprise Security, the same role and saml group has access to all the indexes, On the Splunk Enterprise i am part of 3 roles(A, B, C) which has search filters but I am already part of role D which has access to all indexes but when I am trying to search any data, I am not getting any data, But On Enterprise Security SH, I am able to view all the data as expected.

Is it something like precedence issue on Splunk Enterprise SH that is causing the issue?Please help me.

 

 

Thanks

0 Karma

marnall
Motivator

At first glance I would suspect that the search filters for your roles are contradicting each other and filtering out all events.

E.g. if you have the following roles with search filters:

ROLE A - (index=index1 sourcetype=something)

ROLE B - (index=index2 sourcetype=something)

Then if you have role A and B, then Splunk will force you to search with "(index=index1 sourcetype=something) (index=index2 sourcetype=something)" which will retrieve 0 events because none exist in both index1 and index2 at the same time.

Are you able to post your sanitized search filters to look for contradictory filters?

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...