Splunk ITSI

ITSI - capability \"execute-notable_event_action\

abarneb
Explorer

I'm seeing a lot of these errors regarding the capability \"execute-notable_event_action:

2017-03-10T16:08:52,445 ERROR [itsiruleengine-akka.actor.default-dispatcher-8] EventOperations:599 - HTTP 403 -- {"message":"(403, '\"splunk-system-user\" does not have the capability \"execute-notable_event_action\"')"}

/opt/splunk/etc/apps/itsi/default/authorize.conf:

Notable Event actions

read-notable_event_action = enabled
execute-notable_event_action = enabled

If I try to assign a notable event nothing happens, so I suspect that this is related. My user has the ito_admin/analyst/user roles granted.

Many thanks in advance 🙂

Tags (2)
0 Karma
1 Solution

abarneb
Explorer

The issue was resolved after having granting the ITSI roles to the admin role.

View solution in original post

0 Karma

abarneb
Explorer

The issue was resolved after having granting the ITSI roles to the admin role.

0 Karma

abarneb
Explorer

Turned out that the admin role was lacking the itsi roles. The error disappreared after having granted these roles.

0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...