Splunk® Enterprise Security

Troubleshoot Splunk Enterprise Security

Troubleshoot new users not displaying in the analyst queue

Issue

New users added to Splunk Web might not be displayed for a few minutes in the Owner drop-down on the Analyst queue or when you select a finding from the Analyst queue to view details on the finding in Splunk Enterprise Security.

Cause

The custom roles that you add are populated in the Permissions Manager page of Splunk Enterprise Security within 60 seconds so that you can enable specific access control lists (ACLs).

Solution

Wait for a few minutes so that the new user that you created appears on the Owner drop-down of the Analyst queue and when you view details of a finding on the Mission Control page.

See also

For more information on configuring users and roles in Splunk Enterprise Security, see the product documentation:

Last modified on 14 June, 2024
Troubleshoot missing contributing events for findings in Splunk Enterprise Security   Troubleshoot for adaptive response actions not displaying

This documentation applies to the following versions of Splunk® Enterprise Security: 8.0.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters