Splunk Search

SAML users unable to load reports or alerts

tlmayes
Contributor

SAML authenticated users are unable to access either REPORTS or ALERTS from the search app @ ./app/search/reports or from the top level menu @ Settings/Searches, reports, alerts.  When they attempt to access reports from the Search app, the page stalls at "Loading Reports".  When they attempt to filter on reports or alerts from "Settings/Searches, reports, alerts" a small icon appears at the bottom stating "server error".  The reports are listed, but none are accessible.  If the user is provided a URL to any report, everything works fine.  The ability to browse the list is what is broken.  Finally, if a user goes to "Settings/Searches, reports, alerts" and DOES NOT leaves "Type:All", everything works fine.  If the selection is changed to "Type:Reports" or "Type:Alerts" the error appears at the bottom

Debug logs do not reveal anything obvious

The permissions used for the SAML users is the default "power" role.  I tried moving test users to Admin role, no change.  Also, all local authenticated users in the same role work fine

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...