Splunk IT Service Intelligence

ITSI : Backup and Restore - Error - ItoaAccessDeniedError

Path Finder

I am trying to take a backup in itsi-stg(I) and restore in team-stg(T).
The user has full admin rights including itoa_admin. And meta files has write privilege over collections/itsi_backup_restore_queue.
Still, I get below error when I do the restore :

2019-02-14 15:31:47,310 ERROR [itsi.controllers.itoa_rest_interface_provider] [__init__] [exception] [61544] Access denied. You do not have permission to create this object. Traceback (most recent call last): File "/opt/apps/splunk/etc/apps/SA-ITOA/lib/migration/migration.py", line 187, in migration_bulk_save_to_kvstore handler.migration_save_single_object_to_kvstore(object_type, validation, dupname_tag) File "/opt/apps/splunk/etc/apps/SA-ITOA/lib/migration/object_interface/itoa_migration_interface.py", line 120, in migration_save_single_object_to_kvstore dupname_tag=dupname_tag) File "/opt/apps/splunk/etc/apps/SA-ITOA/lib/ITOA/itoa_common.py", line 878, in save_batch dupname_tag) File "/opt/apps/splunk/etc/apps/SA-ITOA/lib/ITOA/itoa_object.py", line 385, in save_batch logger) ItoaAccessDeniedError: Access denied. You do not have permission to create this object.

Could you please provide any inputs or suggestions.

Situation take back up in environment I and restore in I - Works
Situation take back up in environment T and restore in T - Works
Situation take back up in environment I and restore in T - Not Working Error - ItoaAccessDeniedError

0 Karma

Splunk Employee
Splunk Employee

Look like it could be a splunk role permission issue.

  • Check if you are member of the "admin" role and of the "itoa-admin" role, and make sure that some of their default capabilities were not removed,
  • Verify that ITSI teams have the proper roles listed under.

The other possibility is that the path of $SPLUNK_HOME on the 2 environments are different, and the backup is looking for a folder path that does not exist/is not accessible ?

0 Karma


Try sending your backup file to temp folder of your destination and then move it to respected path.

0 Karma

Path Finder


Restore job "FullRestore_XXXXX_1" has failed. Error: Restore failed, check the related log.
2/15/2019, 2:57:35 PM
Failures occurred while attempting to import some IT Service Intelligence settings from configuration files for apps and modules. Check the logs to get information about which settings failed to be imported.
2/15/2019, 2:57:34 PM
Failed to upgrade IT Service Intelligence.
2/15/2019, 2:57:29 PM
Validating IT Service Intelligence configuration. While validation is in process, the application is not accessible.
2/15/2019, 2:57:26 PM

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...

.conf23 Registration is Now Open!

Time to toss the .conf-etti 🎉 —  .conf23 registration is open!   Join us in Las Vegas July 17-20 for ...