Splunk Search

splunk dbx query error with non-admin - PARSER: Applying intentions failed Unknown search command 'dbinfo'.

jona_sc
New Member

splunk dbx query error with non-admin

Admin user can view the database info and query database.
but non-admin user will export the error like:

Applying intentions failed Unknown search command 'dbinfo'.
Unknown search command 'dbquery'.

It had config the file of
\Splunk\etc\apps\dbx\metadata

============================================================================================

[views/dbquery]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
owner = nobody
version = 5.0.2
modtime = 1366188201.640625000

[views/dbxstatus]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
owner = nobody
version = 5.0.2
modtime = 1366188198.562500000

[commands/dbquery]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
export = system
owner = nobody
version = 5.0.2
modtime = 1366188247.484375000

[views/dbinfo]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
owner = nobody
version = 5.0.2
modtime = 1366188207.062500000

[commands/dbinfo]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
export = system
owner = nobody
version = 5.0.2
modtime = 1366188239.125000000

[commands/dbinput]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
export = system
owner = nobody
version = 5.0.2
modtime = 1366188243.671875000

[commands/dbmonpreview]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
export = none
owner = nobody
version = 5.0.2
modtime = 1366188220.500000000

[commands/dboutput]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
owner = nobody
version = 5.0.2
modtime = 1366188245.500000000

[nav/default]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
owner = nobody
version = 5.0.2
modtime = 1366188217.515625000

[views/home]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
owner = nobody
version = 5.0.2
modtime = 1366189110.531250000

[savedsearches/DB%20Connect%20Debug%20Log]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
owner = nobody
version = 5.0.2
modtime = 1366188214.781250000

[savedsearches/Recent%20DB%20Connect%20errors]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
owner = nobody
version = 5.0.2
modtime = 1366188212.265625000

[savedsearches/Recent%20Java%20Bridge%20errors]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
owner = nobody
version = 5.0.2
modtime = 1366188210.171875000

[props/dbmon%3Amkv/REPORT-mkv]
access = read : [ admin, db_admin ], write : [ admin, db_admin ]
owner = nobody
version = 5.0.2
modtime = 1366188250.343750000

[transforms/dbx-mkv]
access = read : [ admin, db_admin ], write : [ admin, db_admin ]
owner = nobody
version = 5.0.2
modtime = 1366188254.078125000

[props/dbx_debug/EXTRACT-fields]
access = read : [ admin, db_admin ], write : [ admin, db_admin ]
owner = nobody
version = 5.0.2
modtime = 1366188252.296875000

[app/install/state]
version = 5.0.2
modtime = 1366187915.203125000

Tags (2)
0 Karma
1 Solution

Dan
Splunk Employee
Splunk Employee

I think you should try the suggestion mentioned here http://splunk-base.splunk.com/answer_link/76048/

View solution in original post

0 Karma

Dan
Splunk Employee
Splunk Employee

I think you should try the suggestion mentioned here http://splunk-base.splunk.com/answer_link/76048/

0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...