Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

After adding a user to only one search head in a search head cluster, why is the user unable to see all saved search results?

$
0
0
I have a search head cluster and have created a custom role (authorize.conf), which has been deployed to each SH through a custom app. I added a user "xyz" to only one SH so that the user only uses a particular SH. Everything seems fine except that the user is not able to see all the saved search results. Error message when I use loadjob command: Error in 'SearchOperator:loadjob': error accessing https://127.0.0.1:8089/services/search/jobs/scheduler__admin__search__RMD5fc0cc9974bfd0925_at_1453203840_3134_10368B48-6A36-4C42-9AA2-48213D3E4950/?output_mode=json, statusCode=403, description=Forbidden However, when I added the user to all the SHs, there were no errors. My question is, did the issue happen because of not adding the user to all SHs, or because of a capability issue in authorize.conf? Thanks Ishaan

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>