Splunk ITSI

IT Essential Work - Failed to retrieve entity status breakdown. Error: insufficient permission to access this resource

corti77
Contributor

In the way to test ITSI, I first installed IT Essentials Work on my single standalone splunk server

following the instruction from the link 
https://docs.splunk.com/Documentation/ITEWork/4.9.2/Install/Install#Install_IT_Essentials_Work_on_a_...

I simply stop the service, unzip the tgz and start splunk.

once done, I go to the essential work app and I get the following error on the infrastructure overview

corti77_1-1627990033567.png

any idea of what could be happening? I could not find anything in the logs so far.

thanks

 

0 Karma
1 Solution

corti77
Contributor

I finally solved the permissions issue. Thanks a lot for the hint.

I just added the itoa roles in the inherence of the role admin. My user belonged to the admin role, so after I logged out and in, the error in the itsi dashboard disappeared.

 

https://community.splunk.com/t5/Splunk-IT-Service-Intelligence/Why-is-the-fresh-install-of-ITSI-3-1-...

 

View solution in original post

sweetie
Explorer

Hi @corti77 , Where exactly do we need to add the itoa_role in Splunk to solve this issue? Thanks

0 Karma

yannK
Splunk Employee
Splunk Employee

Look in the ITSI default authorize.conf, you will see what is expected.

( file in $SPLUNK_HOME/etc/apps/itsi/default/authorize.conf)

[role_admin]
importRoles = itoa_admin;itoa_analyst;itoa_user;power;user

 

if you have a customized role, (usually in $SPLUNK_HOME/etc/system/local/authorize.conf), this one has precedence, and you may be missing the itoa rolse in inheritance of your admin role.

You can simply edit your "admin" role from the UI > setting > roles, and add the missing inheritances. (and keep any extra ou may have added)

 

0 Karma

sweetie
Explorer

Thank you, it helped. 

0 Karma

yannK
Splunk Employee
Splunk Employee

Could it be a role issue, 
check if your user is member or inherit from the role itoa_user (or itoa_analyst, or itoa_admin) ?

corti77
Contributor

I just double checked it and indeed I am using an admin user that does not have those role assigned. The weird thing is that I tried to add the roles to my user and they dont stick on the user. I add roles, click on Save button and nothing seems to happen.

Any idea about what would be happening?

0 Karma

corti77
Contributor

I finally solved the permissions issue. Thanks a lot for the hint.

I just added the itoa roles in the inherence of the role admin. My user belonged to the admin role, so after I logged out and in, the error in the itsi dashboard disappeared.

 

https://community.splunk.com/t5/Splunk-IT-Service-Intelligence/Why-is-the-fresh-install-of-ITSI-3-1-...

 

rassul_kv
Engager

I have the same problem

0 Karma
Get Updates on the Splunk Community!

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...