Splunk ITSI

ITSI - capability \"execute-notable_event_action\

abarneb
Explorer

I'm seeing a lot of these errors regarding the capability \"execute-notable_event_action:

2017-03-10T16:08:52,445 ERROR [itsiruleengine-akka.actor.default-dispatcher-8] EventOperations:599 - HTTP 403 -- {"message":"(403, '\"splunk-system-user\" does not have the capability \"execute-notable_event_action\"')"}

/opt/splunk/etc/apps/itsi/default/authorize.conf:

Notable Event actions

read-notable_event_action = enabled
execute-notable_event_action = enabled

If I try to assign a notable event nothing happens, so I suspect that this is related. My user has the ito_admin/analyst/user roles granted.

Many thanks in advance 🙂

Tags (2)
0 Karma
1 Solution

abarneb
Explorer

The issue was resolved after having granting the ITSI roles to the admin role.

View solution in original post

0 Karma

abarneb
Explorer

The issue was resolved after having granting the ITSI roles to the admin role.

0 Karma

abarneb
Explorer

Turned out that the admin role was lacking the itsi roles. The error disappreared after having granted these roles.

0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...