Splunk Search

SAML users unable to load reports or alerts

tlmayes
Contributor

SAML authenticated users are unable to access either REPORTS or ALERTS from the search app @ ./app/search/reports or from the top level menu @ Settings/Searches, reports, alerts.  When they attempt to access reports from the Search app, the page stalls at "Loading Reports".  When they attempt to filter on reports or alerts from "Settings/Searches, reports, alerts" a small icon appears at the bottom stating "server error".  The reports are listed, but none are accessible.  If the user is provided a URL to any report, everything works fine.  The ability to browse the list is what is broken.  Finally, if a user goes to "Settings/Searches, reports, alerts" and DOES NOT leaves "Type:All", everything works fine.  If the selection is changed to "Type:Reports" or "Type:Alerts" the error appears at the bottom

Debug logs do not reveal anything obvious

The permissions used for the SAML users is the default "power" role.  I tried moving test users to Admin role, no change.  Also, all local authenticated users in the same role work fine

Labels (1)
0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...