Activity Feed
- Got Karma for Re: Admin can't see users with a certain role and we can't take out the "grantableRoles = admin" option. 09-14-2023 01:53 AM
- Got Karma for Re: Admin can't see users with a certain role and we can't take out the "grantableRoles = admin" option. 09-01-2020 02:21 AM
- Karma Re: After Updating the Add-on for Windows receive error "Could not load lookup=LOOKUP-app4_for_windows_security" for gurlest. 06-05-2020 12:50 AM
- Got Karma for Re: Admin can't see users with a certain role and we can't take out the "grantableRoles = admin" option. 06-05-2020 12:50 AM
- Got Karma for Re: HttpPubSubConnection - Unable to parse message from PubSubSvr. 06-05-2020 12:50 AM
- Got Karma for Re: Can you please suggest the right capabilities and inheritance that we should use to create/edit roles?. 06-05-2020 12:50 AM
- Got Karma for Re: Can you please suggest the right capabilities and inheritance that we should use to create/edit roles?. 06-05-2020 12:50 AM
- Got Karma for Re: Can you please suggest the right capabilities and inheritance that we should use to create/edit roles?. 06-05-2020 12:50 AM
- Got Karma for Re: Can you please suggest the right capabilities and inheritance that we should use to create/edit roles?. 06-05-2020 12:50 AM
- Got Karma for Re: Admin can't see users with a certain role and we can't take out the "grantableRoles = admin" option. 06-05-2020 12:50 AM
- Got Karma for Re: Admin can't see users with a certain role and we can't take out the "grantableRoles = admin" option. 06-05-2020 12:50 AM
- Got Karma for Re: Admin can't see users with a certain role and we can't take out the "grantableRoles = admin" option. 06-05-2020 12:50 AM
- Karma Re: Wrong retention caused buckets to freeze in cluster- Need to restore frozen data for scheng_splunk. 06-05-2020 12:49 AM
- Got Karma for Re: Indexes are not available to select from "Available search indexes" during role creation since upgrade to 7.0.0. 06-05-2020 12:49 AM
- Got Karma for Re: Indexes are not available to select from "Available search indexes" during role creation since upgrade to 7.0.0. 06-05-2020 12:49 AM
- Got Karma for Re: Indexes are not available to select from "Available search indexes" during role creation since upgrade to 7.0.0. 06-05-2020 12:49 AM
- Got Karma for Re: Indexes are not available to select from "Available search indexes" during role creation since upgrade to 7.0.0. 06-05-2020 12:49 AM
- Got Karma for Re: Indexes are not available to select from "Available search indexes" during role creation since upgrade to 7.0.0. 06-05-2020 12:49 AM
- Got Karma for Re: Indexes are not available to select from "Available search indexes" during role creation since upgrade to 7.0.0. 06-05-2020 12:49 AM
- Got Karma for Re: Indexes are not available to select from "Available search indexes" during role creation since upgrade to 7.0.0. 06-05-2020 12:49 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 |
10-14-2024
06:30 AM
Hello @tchimento_splun @rjteh_splunk looks like this bug is still happening in 9.3.0
... View more
07-31-2019
01:01 PM
Yes, quite a few. However, I get the same message as above when I do a search for : event_id_to_action_lookup
... View more
05-22-2020
04:15 AM
Thanks for the perfect answer.
... View more
04-28-2019
03:30 AM
1 Karma
Hi @analiaeg ,
There could be several reasons to that log message...
Depending on the other messages before/after it, there could be a network connection issue between your Deployment client (DC) and Deployment server (DS). Please make sure there is no firewalls in between blocking the 8089 port that is needed for communication. One way to test the connection between the DS and DC is the telnet command to port 8089 on the DC to DS. Usually it is the case where there is a network connectivity issue somewhere with most customers.
Or there have been cases where the sslPassword in server.conf under the "[sslConfig]" stanza maybe have been changed from the default (if you are using the default Splunk server.pem cert). Otherwise, it may not be the correct sslPassword for your own imported SSL server certificate.
More information about this stanza can be found here for your reference.
> server.conf
sslPassword = <password>
* Server certificate password.
* Default is "password".
http://docs.splunk.com/Documentation/Splunk/7.1.1/admin/Serverconf
... View more
04-28-2019
03:13 AM
If you have a LB in front of the SH(s), you can try to configure the splunk web fqdn in SAML configuration > Advanced Settings > "Fully qualified domain name or IP of the load balancer". This will configure the fqdn of the LB in authorize.conf.
... View more
10-18-2018
05:12 PM
4 Karma
The "edit_roles_grantable" capability will only allow the user to create/edit the role if they have listed the roles in "Inheritance" section on the custom role.
For example, if you want to create/edit a power role, the user must at least be assigned a custom role which inherits another custom role which has power capabilities or the power role itself (as shown below).
Once the user logs in and attempts to create a new role, they will be able to only select from the following list.
However, if you would like the user to be able to inherit from all available roles, you can add the "edit_roles" capability to achieve this. Documented here:
About defining roles with capabilities
... View more
12-19-2017
08:22 AM
Yes it worked!
I got the authorize.conf from 6.6.3 version and placed it on the $SPLUNK_HOME/etc/apps/search/local/data/ui/manager folder and it fixed the issue after I debug/refreshed splunk Search Head.
Thanks!
P.S. - I also had an issue while upgrading from 6.6.3 to 7.0.1 where I couldn't make any search. The fix was to enable Distributed Search again and restart the Search Head. The fix is here explained: https://answers.splunk.com/answers/208043/unable-to-run-any-search-query-warn-search-filters.html
... View more