<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic cluster-identity-get failed in Data Infrastructure Insights</title>
    <link>https://community.netapp.com/t5/Data-Infrastructure-Insights/cluster-identity-get-failed/m-p/447983#M214</link>
    <description>&lt;P&gt;I originally had Data Collectors setup in Cloud Insights using cluster admin credentials.&amp;nbsp; I just followed the steps at&amp;nbsp;&lt;A href="https://docs.netapp.com/us-en/cloudinsights/task_add_collector_svm.html#a-note-about-permissions" target="_blank" rel="noopener"&gt;https://docs.netapp.com/us-en/cloudinsights/task_add_collector_svm.html#a-note-about-permissions&lt;/A&gt;&amp;nbsp;in the "Permissions when adding via&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Cluster Management IP&lt;/STRONG&gt;:"&amp;nbsp; section and the cmddirs in the role that was created all match and the ssh and ontapi access were granted, but when I switched the credentials in the collector to this new account the collectors fail and I get this when I test the connection "&lt;SPAN&gt;Configuration: Failed to execute test command on device - NetApp ONTAP zapi communication failed: cluster-identity-get failed: Insufficient privileges: user 'csuser' does not have read access to this resource."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Oriole::&amp;gt; security login role show -vserver Oriole -role csrole
           Role          Command/                                      Access
Vserver    Name          Directory                               Query Level
---------- ------------- --------- ----------------------------------- --------
Oriole     csrole        DEFAULT                                       none
                         event catalog                                 all
                         event filter                                  all
                         event notification                            all
                         event notification destination                all
                         network interface                             readonly
                         security certificate                          all
                         version                                       readonly
                         volume                                        readonly
                         volume snapshot       -snapshot cloudsecure_* all
                         vserver                                       readonly
                         vserver fpolicy                               all
12 entries were displayed.&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;Oriole::&amp;gt; security login show -role csrole

Vserver: Oriole
                                                                 Second
User/Group                 Authentication                 Acct   Authentication
Name           Application Method        Role Name        Locked Method
-------------- ----------- ------------- ---------------- ------ --------------
csuser         ontapi      password      csrole           no     none
csuser         ssh         password      csrole           no     none
2 entries were displayed.&lt;/LI-CODE&gt;</description>
    <pubDate>Wed, 04 Jun 2025 09:44:22 GMT</pubDate>
    <dc:creator>Stormont</dc:creator>
    <dc:date>2025-06-04T09:44:22Z</dc:date>
    <item>
      <title>cluster-identity-get failed</title>
      <link>https://community.netapp.com/t5/Data-Infrastructure-Insights/cluster-identity-get-failed/m-p/447983#M214</link>
      <description>&lt;P&gt;I originally had Data Collectors setup in Cloud Insights using cluster admin credentials.&amp;nbsp; I just followed the steps at&amp;nbsp;&lt;A href="https://docs.netapp.com/us-en/cloudinsights/task_add_collector_svm.html#a-note-about-permissions" target="_blank" rel="noopener"&gt;https://docs.netapp.com/us-en/cloudinsights/task_add_collector_svm.html#a-note-about-permissions&lt;/A&gt;&amp;nbsp;in the "Permissions when adding via&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Cluster Management IP&lt;/STRONG&gt;:"&amp;nbsp; section and the cmddirs in the role that was created all match and the ssh and ontapi access were granted, but when I switched the credentials in the collector to this new account the collectors fail and I get this when I test the connection "&lt;SPAN&gt;Configuration: Failed to execute test command on device - NetApp ONTAP zapi communication failed: cluster-identity-get failed: Insufficient privileges: user 'csuser' does not have read access to this resource."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Oriole::&amp;gt; security login role show -vserver Oriole -role csrole
           Role          Command/                                      Access
Vserver    Name          Directory                               Query Level
---------- ------------- --------- ----------------------------------- --------
Oriole     csrole        DEFAULT                                       none
                         event catalog                                 all
                         event filter                                  all
                         event notification                            all
                         event notification destination                all
                         network interface                             readonly
                         security certificate                          all
                         version                                       readonly
                         volume                                        readonly
                         volume snapshot       -snapshot cloudsecure_* all
                         vserver                                       readonly
                         vserver fpolicy                               all
12 entries were displayed.&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;Oriole::&amp;gt; security login show -role csrole

Vserver: Oriole
                                                                 Second
User/Group                 Authentication                 Acct   Authentication
Name           Application Method        Role Name        Locked Method
-------------- ----------- ------------- ---------------- ------ --------------
csuser         ontapi      password      csrole           no     none
csuser         ssh         password      csrole           no     none
2 entries were displayed.&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 04 Jun 2025 09:44:22 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Data-Infrastructure-Insights/cluster-identity-get-failed/m-p/447983#M214</guid>
      <dc:creator>Stormont</dc:creator>
      <dc:date>2025-06-04T09:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: cluster-identity-get failed</title>
      <link>https://community.netapp.com/t5/Data-Infrastructure-Insights/cluster-identity-get-failed/m-p/447984#M215</link>
      <description>&lt;P&gt;That looks like the requirements doc for Workload Security aka Cloud Secure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.netapp.com/us-en/cloudinsights/task_dc_na_cdot.html#ontap-power-metrics" target="_blank"&gt;https://docs.netapp.com/us-en/cloudinsights/task_dc_na_cdot.html#ontap-power-metrics&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This link should be more useful for the getting Cloud Insights collecting with a least privilege user&lt;/P&gt;</description>
      <pubDate>Sat, 30 Sep 2023 00:47:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Data-Infrastructure-Insights/cluster-identity-get-failed/m-p/447984#M215</guid>
      <dc:creator>ostiguy</dc:creator>
      <dc:date>2023-09-30T00:47:11Z</dc:date>
    </item>
    <item>
      <title>Re: cluster-identity-get failed</title>
      <link>https://community.netapp.com/t5/Data-Infrastructure-Insights/cluster-identity-get-failed/m-p/447985#M216</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Sat, 30 Sep 2023 01:57:50 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Data-Infrastructure-Insights/cluster-identity-get-failed/m-p/447985#M216</guid>
      <dc:creator>Stormont</dc:creator>
      <dc:date>2023-09-30T01:57:50Z</dc:date>
    </item>
  </channel>
</rss>

