Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

Problem with a user's ability to set permissions on a saved search

$
0
0

I have created a role for a group of users for whom we are collecting their Windows Exchange logs and Windows events logs. This role inherits from 'user'. Things have been fine, but one user wanted to share a saved search with other members of his group (user_wsg). The search is shows in the manager (Searches and Reports) as part of the Search App, and it under sharing it is the default 'Private', as expected. But there is no Permissions link next to 'Private' as I am used to seeing, so this is a problem and I'd like to know how to best approach remedying that.

The documentation on roles seems to say that the role of user allows changing one's own permissions on searches. But The role of user does not have write access in the permissions of the search app, and one splunk answer I read said that if the user does not have write permissions in the app they can't change the permissions of a saved search. So this is a dilemma for me. Is there a good way around this?

I've no desire to make the role inherit from power-user, and I really don't want to change allow the user role to have write-access in the search app. Can I have this one person in the group but abstract him off another level and given just him the ability to share with his co-workers somehow?

The /opt/splunk/etc/system/local/authorize.conf file stanza for this role looks like this:

    [role_user_wsg]
importRoles = user
rtSrchJobsQuota = 0
srchDiskQuota = 0
srchFilter = tag::host=oit_wsg
srchIndexesAllowed = *
srchIndexesDefault = *
srchJobsQuota = 0

Viewing all articles
Browse latest Browse all 13053

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>