Observability

Audit Events repeatedly log an "Access denied" exception for the GetSupportedMetrics verb (Orion.Nodes / Orion.Volumes / Orion.NPM.Interfaces) for non-administrator users in the SolarWinds Platform

This article provides information about an issue in the SolarWinds Platform where the Audit Events view is flooded with repeated "Access denied" exception messages generated whenever a non-administrator user opens a Node Details, Volume Details, or Interface Details page. The denied operation is the real-time polling verb GetSupportedMetrics. The messages are benign (they do not interrupt monitoring, polling, or alerting) but can quickly fill the Audit Events log with dozens of identical entries per minute.

First published date

6/29/2026 10:18 PM

Last published date

6/29/2026 11:10 PM

Overview

After upgrading the SolarWinds Platform, administrators may notice a large volume of identical "Access denied" entries in Audit Events (Settings > All Settings > Audit Events). The entries appear with a red error status and a message type of "Audit Event".

The events are triggered when a user who is not an administrator (and who does not have the "Allow Real-Time Polling" permission) views any of the following pages:

  • Node Details
  • Volume Details
  • Interface Details

When one of these pages loads, it attempts to invoke the real-time polling verb GetSupportedMetrics against the corresponding entity. The SolarWinds Information Service (SWIS) denies the request for that user, and each denial is written to the Audit Events log. Because these detail pages poll frequently, the same message repeats rapidly, often several times within the same second.

Sample messages that may be seen in the Audit Events view (account name, date/time, and IP address are environment-specific and shown here as generic values):

01/15/2025 9:01:46 AM   Audit Event   User limited_user triggered "Access denied" exception by invoking the verb Orion.Volumes.GetSupportedMetrics.
01/15/2025 9:01:46 AM   Audit Event   User limited_user triggered "Access denied" exception by invoking the verb Orion.Nodes.GetSupportedMetrics.
01/15/2025 9:01:46 AM   Audit Event   User limited_user triggered "Access denied" exception by invoking the verb Orion.NPM.Interfaces.GetSupportedMetrics.

Figure 1 shows the Audit Events view filling with the repeated entries.

Figure 1: Audit Events repeatedly logging "Access denied" exceptions for Orion.Volumes.GetSupportedMetrics, Orion.Nodes.GetSupportedMetrics, and Orion.NPM.Interfaces.GetSupportedMetrics for a non-administrator user.

A corresponding access-denied fault for the same verb may also be visible in the SolarWinds Information Service log, similar to the following generic example:

System.ServiceModel.FaultException`1[SolarWinds.InformationService.Contract2.InfoServiceFaultContract]:
Orion.Volumes.GetSupportedMetrics failed, check fault information.
Access to Orion.Volumes.GetSupportedMetrics verb denied.
(Fault Detail is equal to InfoServiceFaultContract, ErrorCode=00000014,
UserMessage='Access to Orion.Volumes.GetSupportedMetrics verb denied.'
[ SolarWinds.Data.AccessDeniedException: Access to Orion.Volumes.GetSupportedMetrics verb denied. ]).

Key indicators that confirm a match for this issue:

  • The Audit Events message text is "User {account}; triggered Access denied exception by invoking the verb Orion.{entity};.GetSupportedMetrics." 
  • The denied verb is always GetSupportedMetrics on the Nodes, Volumes, or NPM Interfaces entity.
  • The affected user is a non-administrator account that does not have "Allow Real-Time Polling" enabled.
  • The same operation does not generate the entries when performed by an administrator account.
  • Monitoring, polling, and alerting continue to function normally; only the audit log is affected.

Product section

Hybrid Cloud Observability

Cause

The GetSupportedMetrics verb was moved to the Collector as part of the real-time polling (RTP) feature migration. During that change, the SWIS schema access control for the RTP verbs on the Nodes, Volumes, and Interfaces entities was scoped to administrators only, instead of being available to every account that holds the real-time polling right. As a result, when a non-administrator account opens a details page that invokes GetSupportedMetrics, SWIS denies the call and writes an Audit Event for each attempt. Because the detail pages invoke the verb repeatedly, the denials accumulate quickly in the Audit Events log.

 

The denials are cosmetic. The user is still able to view the page and all standard monitoring continues to work; the only effect is the repeated audit-log noise.

Resolution

Upgrade the SolarWinds Platform to a version that contains the corrected SWIS schema access control. After upgrading, the real-time polling verbs are available to accounts with the appropriate rights, and the repeated "Access denied" audit events stop being generated.

Steps:

  1. Plan an upgrade to a SolarWinds Platform version that includes the fix (the corrected access control is included in the 2025.4 and later; it was also delivered to 2025.2.1). Confirm the current fixed build before scheduling the upgrade.
  2. Upgrade the primary polling engine and any additional polling engines/web servers following the standard SolarWinds Platform upgrade process.
  3. Verify the fix:
    • Log in as the affected non-administrator user.
    • Open a Node Details page, a Volume Details page, and an Interface Details page.
    • Log in as an administrator and open Settings > All Settings > Audit Events.
    • Confirm that no new "Access denied" / GetSupportedMetrics entries are generated for that user.
  4. (Optional) Clear the existing audit-log noise by selecting the old entries in the Audit Events view and choosing Clear Selected Messages.

Interim mitigation (if an upgrade cannot be scheduled immediately):

  • The messages are benign and can be safely ignored until the upgrade is performed.
  • Alternatively, enabling the "Allow Real-Time Polling" permission for the affected account or group (Settings > All Settings > Manage Accounts > Edit > Performance Analysis Settings) allows the GetSupportedMetrics verb to succeed and stops the denials from being recorded. Validate on a single account first.