I'm seeing a lot of these errors regarding the capability \"execute-notable_event_action:
2017-03-10T16:08:52,445 ERROR [itsiruleengine-akka.actor.default-dispatcher-8] EventOperations:599 - HTTP 403 -- {"message":"(403, '\"splunk-system-user\" does not have the capability \"execute-notable_event_action\"')"}
/opt/splunk/etc/apps/itsi/default/authorize.conf:
read-notable_event_action = enabled
execute-notable_event_action = enabled
If I try to assign a notable event nothing happens, so I suspect that this is related. My user has the ito_admin/analyst/user roles granted.
Many thanks in advance 🙂
The issue was resolved after having granting the ITSI roles to the admin role.
The issue was resolved after having granting the ITSI roles to the admin role.
Turned out that the admin role was lacking the itsi roles. The error disappreared after having granted these roles.