Splunk Search

Permissions for index access

jcbrendsel
Path Finder

We are running the new splunk universal forwarder on an application server. It has the standard setup to recursively index the /var/log directory.

In there we have an application subdirectory:

/var/log/tvschedules/import.log

I can search the contents of this log using any user with admin privileges, but unfortunately user with poweruser and user roles get empty search results.

Any ideas on what could be causing the issue?

Tags (3)
0 Karma

joshd
Builder

Go into the manager, then into access controls, click on roles, select the relevant role and make sure the relevant index is applied to their role. If the index this file is going into is on the left hand side under "Indexes" (and not in the grey box on the right hand side) then you need to click on the green arrow beside the index name so it gives the role permission to search on that index. Also you may wish to make it a part of the "Indexes searched by default" so that when they run their search they do not need to explicitly specify the index=whatever

cheers

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...