Refine your search:

We've recently changed out our servers and when I use the searches against these new hosts using my user I am not getting the log results like I was with the old servers. We are definitely getting the log data but my user just can't access it. However, the admin user is getting the results. Furthermore any searches that are owned by my user do not get the results when they send out scheduled e-mail alerts, but the ones owned by the admin user do get results.

Is there a setting somewhere for these new hosts that I need to change?

asked 23 Jan, 11:50

jdibble's gravatar image

jdibble
10
accept rate: 0%


2 Answers:

Does your ordinary user role have the right to access the index where the events get stored?

Have a look under

manager -> access controls -> roles -> <your_user_role>

Near the bottom of the page are the two settings for "indexes searched by default" and "indexes".

There may also be "search restrictions" added for that user role, see the top of the page, just under "default application".

UPDATE: The interesting thing is whether there is a difference between what indexes the admin role and your ordinary user role has access to. If the access rights are the same, are the same indexes searched by default? Also, are there any search restrictions for your ordinary user role (usually there are no restrictions on placed on the admin role).

Hope this helps,

Kristian

link

answered 25 Jan, 02:03

kristian.kolb's gravatar image

kristian.kolb
3.4k210
accept rate: 30%

edited 26 Jan, 07:33

I tried that and found that my user does have the admin user role. I had a couple of other user roles as well and tried removing them, logging out and back in, and searching again but the results are the same.

(25 Jan, 06:05) jdibble

In regards to your update, as I said before I had tried removing my additional user roles so that my user only has the admin user role. (which the actual admin user has)

(26 Jan, 11:41) jdibble

Possibilities:

  • You have different allowed indexes or default indexes
  • Your search depends on fields/field extractions/other objects that are either private or in an app that is not accessible to the user.
link

answered 26 Jan, 08:06

gkanapathy's gravatar image

gkanapathy ♦
26.4k1622
accept rate: 42%

good point on the second one /k

(26 Jan, 08:14) kristian.kolb

How would I go about checking the second one?

(26 Jan, 11:41) jdibble

you could look for any "Private" items owned by "admin" in the Manager GUI, perhaps under the "All Configurations" section.

(26 Jan, 12:35) gkanapathy ♦
Post your answer
toggle preview

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×98
×59
×15
×3

Asked: 23 Jan, 11:50

Seen: 337 times

Last updated: 26 Jan, 12:35

Copyright © 2005-2012 Splunk, Inc. All rights reserved.