Cortex XDR: Default Viewer Role shows "Failed to run query" on Dashboard with custom Widgets

Cortex XDR: Default Viewer Role shows "Failed to run query" on Dashboard with custom Widgets

3904
Created On 06/17/24 13:33 PM - Last Modified 06/17/24 20:44 PM


Symptom


  • Users who are granted the default Cortex XDR Role named Viewer may have issues viewing Dashboards or any Widgets based on XQL Queries that are run by the Widget.
    • This can present the two errors:
      • "Failed to run query"
      • Permission Notice - Your current role is preventing you from using all the components in this page. Contact your administrator to adjust your access permissions."


Environment


  • Cortex XDR or XDR


Cause


  • Widgets being used by either a default Dashboard or a custom Dashboard may run on XQL Queries
  • By default, the Viewer role gives View-only access to the Query Center activities, whereas View/Edit is needed to view any Widgets that are running XQL Queries, as technically it is re-running them at the time of viewing the Dashboard
  • Any User with only the Viewer role will fail to view any Widgets running XQL Queries for this reason, giving the error "Failed to run query" which then generates the error "Permission Notice - Your current role is preventing you from using all the components in this page. Contact your administrator to adjust your access permissions." at the top of the screen


Resolution


Administrators of the tenant can Clone the Viewer role and edit to have View/Edit permissions for Query Center:
  1. Log in to your tenant
  2. Navigate to Settings > Configurations > Access Management > Roles
  3. Find the Viewer Role, R-click and select Save As New Role
  4. Provide a Role Name, under Incident Response > Investigation > Query Center select View/Edit and click Save
  5. Navigate to Settings > Configurations > Access Management > Users and R-click the user, select Edit User Permissions
  6. Set user's Role as the newly created custom role and click Save


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HDMzCAO&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language