Splunk Search

Why is a user unable to search data from a certain index, even with the permissions and role assigned for the proper app?

sunnyparmar
Communicator

I have one user (scpet) to whom I assigned rights and roles of some apps. Now the user is facing a problem that he is unable to search data from one of the indexes (sc-pet) and the mentioned index comes under (sc_monitoring) app and I gave rights to user to access this app by settings->Users and authentication->Access Control. So kindly suggest what to do in this case?

Thanks

0 Karma
1 Solution

somesoni2
SplunkTrust
SplunkTrust

Did you add access to the index sc-pet to the role which the user scpet is assigned to? (path: Settings » Access controls » Roles » YourUserRole » Indexes)

View solution in original post

somesoni2
SplunkTrust
SplunkTrust

Did you add access to the index sc-pet to the role which the user scpet is assigned to? (path: Settings » Access controls » Roles » YourUserRole » Indexes)

sunnyparmar
Communicator

I am able to do it now.. Issue solved.. Thanks for the Guidance...

0 Karma

anshul0915
Explorer

What is the resoultion i am facing the same issue

0 Karma

sunnyparmar
Communicator

Thanks for replying.. as per your guidance i am doing the same thing by going in (path: Settings » Access controls » Roles » YourUserRole » Indexes) but still not able to search index (sc-pet) by scpet user. Could you please elaborate that there how I have to fill details in all steps. Like in first column Roll name I have mentioned both sc-pet (index) and scpet(user) done by both the way but not able to search so could you please specify that how to fill columns there? Thanks

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...