Splunk ITSI

IT Essential Work - Failed to retrieve entity status breakdown. Error: insufficient permission to access this resource

corti77
Communicator

In the way to test ITSI, I first installed IT Essentials Work on my single standalone splunk server

following the instruction from the link 
https://docs.splunk.com/Documentation/ITEWork/4.9.2/Install/Install#Install_IT_Essentials_Work_on_a_...

I simply stop the service, unzip the tgz and start splunk.

once done, I go to the essential work app and I get the following error on the infrastructure overview

corti77_1-1627990033567.png

any idea of what could be happening? I could not find anything in the logs so far.

thanks

 

0 Karma
1 Solution

corti77
Communicator

I finally solved the permissions issue. Thanks a lot for the hint.

I just added the itoa roles in the inherence of the role admin. My user belonged to the admin role, so after I logged out and in, the error in the itsi dashboard disappeared.

 

https://community.splunk.com/t5/Splunk-IT-Service-Intelligence/Why-is-the-fresh-install-of-ITSI-3-1-...

 

View solution in original post

sweetie
Explorer

Hi @corti77 , Where exactly do we need to add the itoa_role in Splunk to solve this issue? Thanks

0 Karma

yannK
Splunk Employee
Splunk Employee

Look in the ITSI default authorize.conf, you will see what is expected.

( file in $SPLUNK_HOME/etc/apps/itsi/default/authorize.conf)

[role_admin]
importRoles = itoa_admin;itoa_analyst;itoa_user;power;user

 

if you have a customized role, (usually in $SPLUNK_HOME/etc/system/local/authorize.conf), this one has precedence, and you may be missing the itoa rolse in inheritance of your admin role.

You can simply edit your "admin" role from the UI > setting > roles, and add the missing inheritances. (and keep any extra ou may have added)

 

0 Karma

sweetie
Explorer

Thank you, it helped. 

0 Karma

yannK
Splunk Employee
Splunk Employee

Could it be a role issue, 
check if your user is member or inherit from the role itoa_user (or itoa_analyst, or itoa_admin) ?

corti77
Communicator

I just double checked it and indeed I am using an admin user that does not have those role assigned. The weird thing is that I tried to add the roles to my user and they dont stick on the user. I add roles, click on Save button and nothing seems to happen.

Any idea about what would be happening?

0 Karma

corti77
Communicator

I finally solved the permissions issue. Thanks a lot for the hint.

I just added the itoa roles in the inherence of the role admin. My user belonged to the admin role, so after I logged out and in, the error in the itsi dashboard disappeared.

 

https://community.splunk.com/t5/Splunk-IT-Service-Intelligence/Why-is-the-fresh-install-of-ITSI-3-1-...

 

rassul_kv
Engager

I have the same problem

0 Karma
Get Updates on the Splunk Community!

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...