Splunk Search

splunk dbx query error with non-admin - PARSER: Applying intentions failed Unknown search command 'dbinfo'.

jona_sc
New Member

splunk dbx query error with non-admin

Admin user can view the database info and query database.
but non-admin user will export the error like:

Applying intentions failed Unknown search command 'dbinfo'.
Unknown search command 'dbquery'.

It had config the file of
\Splunk\etc\apps\dbx\metadata

============================================================================================

[views/dbquery]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
owner = nobody
version = 5.0.2
modtime = 1366188201.640625000

[views/dbxstatus]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
owner = nobody
version = 5.0.2
modtime = 1366188198.562500000

[commands/dbquery]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
export = system
owner = nobody
version = 5.0.2
modtime = 1366188247.484375000

[views/dbinfo]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
owner = nobody
version = 5.0.2
modtime = 1366188207.062500000

[commands/dbinfo]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
export = system
owner = nobody
version = 5.0.2
modtime = 1366188239.125000000

[commands/dbinput]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
export = system
owner = nobody
version = 5.0.2
modtime = 1366188243.671875000

[commands/dbmonpreview]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
export = none
owner = nobody
version = 5.0.2
modtime = 1366188220.500000000

[commands/dboutput]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
owner = nobody
version = 5.0.2
modtime = 1366188245.500000000

[nav/default]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
owner = nobody
version = 5.0.2
modtime = 1366188217.515625000

[views/home]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
owner = nobody
version = 5.0.2
modtime = 1366189110.531250000

[savedsearches/DB%20Connect%20Debug%20Log]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
owner = nobody
version = 5.0.2
modtime = 1366188214.781250000

[savedsearches/Recent%20DB%20Connect%20errors]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
owner = nobody
version = 5.0.2
modtime = 1366188212.265625000

[savedsearches/Recent%20Java%20Bridge%20errors]
access = read : [ admin, db_admin, power, user ], write : [ admin, db_admin ]
owner = nobody
version = 5.0.2
modtime = 1366188210.171875000

[props/dbmon%3Amkv/REPORT-mkv]
access = read : [ admin, db_admin ], write : [ admin, db_admin ]
owner = nobody
version = 5.0.2
modtime = 1366188250.343750000

[transforms/dbx-mkv]
access = read : [ admin, db_admin ], write : [ admin, db_admin ]
owner = nobody
version = 5.0.2
modtime = 1366188254.078125000

[props/dbx_debug/EXTRACT-fields]
access = read : [ admin, db_admin ], write : [ admin, db_admin ]
owner = nobody
version = 5.0.2
modtime = 1366188252.296875000

[app/install/state]
version = 5.0.2
modtime = 1366187915.203125000

Tags (2)
0 Karma
1 Solution

Dan
Splunk Employee
Splunk Employee

I think you should try the suggestion mentioned here http://splunk-base.splunk.com/answer_link/76048/

View solution in original post

0 Karma

Dan
Splunk Employee
Splunk Employee

I think you should try the suggestion mentioned here http://splunk-base.splunk.com/answer_link/76048/

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...