Splunk IT Service Intelligence

IT Essential Work - Failed to retrieve entity status breakdown. Error: insufficient permission to access this resource

corti77
Communicator

In the way to test ITSI, I first installed IT Essentials Work on my single standalone splunk server

following the instruction from the link 
https://docs.splunk.com/Documentation/ITEWork/4.9.2/Install/Install#Install_IT_Essentials_Work_on_a_...

I simply stop the service, unzip the tgz and start splunk.

once done, I go to the essential work app and I get the following error on the infrastructure overview

corti77_1-1627990033567.png

any idea of what could be happening? I could not find anything in the logs so far.

thanks

 

0 Karma
1 Solution

corti77
Communicator

I finally solved the permissions issue. Thanks a lot for the hint.

I just added the itoa roles in the inherence of the role admin. My user belonged to the admin role, so after I logged out and in, the error in the itsi dashboard disappeared.

 

https://community.splunk.com/t5/Splunk-IT-Service-Intelligence/Why-is-the-fresh-install-of-ITSI-3-1-...

 

View solution in original post

sweetie
Loves-to-Learn Lots

Hi @corti77 , Where exactly do we need to add the itoa_role in Splunk to solve this issue? Thanks

0 Karma

yannK
Splunk Employee
Splunk Employee

Look in the ITSI default authorize.conf, you will see what is expected.

( file in $SPLUNK_HOME/etc/apps/itsi/default/authorize.conf)

[role_admin]
importRoles = itoa_admin;itoa_analyst;itoa_user;power;user

 

if you have a customized role, (usually in $SPLUNK_HOME/etc/system/local/authorize.conf), this one has precedence, and you may be missing the itoa rolse in inheritance of your admin role.

You can simply edit your "admin" role from the UI > setting > roles, and add the missing inheritances. (and keep any extra ou may have added)

 

0 Karma

sweetie
Loves-to-Learn Lots

Thank you, it helped. 

0 Karma

yannK
Splunk Employee
Splunk Employee

Could it be a role issue, 
check if your user is member or inherit from the role itoa_user (or itoa_analyst, or itoa_admin) ?

corti77
Communicator

I just double checked it and indeed I am using an admin user that does not have those role assigned. The weird thing is that I tried to add the roles to my user and they dont stick on the user. I add roles, click on Save button and nothing seems to happen.

Any idea about what would be happening?

0 Karma

corti77
Communicator

I finally solved the permissions issue. Thanks a lot for the hint.

I just added the itoa roles in the inherence of the role admin. My user belonged to the admin role, so after I logged out and in, the error in the itsi dashboard disappeared.

 

https://community.splunk.com/t5/Splunk-IT-Service-Intelligence/Why-is-the-fresh-install-of-ITSI-3-1-...

 

rassul_kv
Engager

I have the same problem

0 Karma
Get Updates on the Splunk Community!

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...