Security

Not able to view Log events if I log in as user

nikhilagrawal
Path Finder

Hi
I have a situation here. Forwarder is pushing data to the indexer and I can see the logs on Search Head if I login as Admin but I cant see same log events if I login as user.

I also able to view logs if I directly login to indexer.
I am certain its permission issue but not able to resolve it. I have tried with Access Control changes.

Please suggest what I am missing here.

Thanks.

Tags (1)
0 Karma

Ayn
Legend

I'm guessing your user doesn't have permission to read from the index that the logs are written to, or some other restrictions have been set on what kind of searches the user can perform. You can check this in the manager (as admin) in the Manager -> Access controls section.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...