Splunk IT Service Intelligence

ITSI - capability \"execute-notable_event_action\

Explorer

I'm seeing a lot of these errors regarding the capability \"execute-notableeventaction:

2017-03-10T16:08:52,445 ERROR [itsiruleengine-akka.actor.default-dispatcher-8] EventOperations:599 - HTTP 403 -- {"message":"(403, '\"splunk-system-user\" does not have the capability \"execute-notableeventaction\"')"}

/opt/splunk/etc/apps/itsi/default/authorize.conf:

Notable Event actions

read-notableeventaction = enabled
execute-notableeventaction = enabled

If I try to assign a notable event nothing happens, so I suspect that this is related. My user has the ito_admin/analyst/user roles granted.

Many thanks in advance 🙂

Tags (2)
0 Karma
1 Solution

Explorer

The issue was resolved after having granting the ITSI roles to the admin role.

View solution in original post

0 Karma

Explorer

The issue was resolved after having granting the ITSI roles to the admin role.

View solution in original post

0 Karma

Explorer

Turned out that the admin role was lacking the itsi roles. The error disappreared after having granted these roles.

0 Karma