<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What capabilities are needed for a non-admin user to update Server Classes and Clients in Settings -&amp;gt; Forwarder Management in Security</title>
    <link>https://community.splunk.com/t5/Security/What-capabilities-are-needed-for-a-non-admin-user-to-update/m-p/459940#M10719</link>
    <description>&lt;P&gt;We've got a special role for non-admin security team members and I'd like some of them to be able to use Forwarder Management (in the Settings menu) to add new clients to a Server Class. I can't figure out what the required Capabilities are that need to be added to their role.&lt;/P&gt;</description>
    <pubDate>Fri, 02 Nov 2018 23:10:51 GMT</pubDate>
    <dc:creator>wrangler2x</dc:creator>
    <dc:date>2018-11-02T23:10:51Z</dc:date>
    <item>
      <title>What capabilities are needed for a non-admin user to update Server Classes and Clients in Settings -&gt; Forwarder Management</title>
      <link>https://community.splunk.com/t5/Security/What-capabilities-are-needed-for-a-non-admin-user-to-update/m-p/459940#M10719</link>
      <description>&lt;P&gt;We've got a special role for non-admin security team members and I'd like some of them to be able to use Forwarder Management (in the Settings menu) to add new clients to a Server Class. I can't figure out what the required Capabilities are that need to be added to their role.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2018 23:10:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/What-capabilities-are-needed-for-a-non-admin-user-to-update/m-p/459940#M10719</guid>
      <dc:creator>wrangler2x</dc:creator>
      <dc:date>2018-11-02T23:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: What capabilities are needed for a non-admin user to update Server Classes and Clients in Settings -&gt; Forwarder Management</title>
      <link>https://community.splunk.com/t5/Security/What-capabilities-are-needed-for-a-non-admin-user-to-update/m-p/459941#M10720</link>
      <description>&lt;P&gt;I personally never gave that capability to anyone. But you could try edit_deployment_client, edit_deployment_server, list_deployment_server capabilities.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:56:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/What-capabilities-are-needed-for-a-non-admin-user-to-update/m-p/459941#M10720</guid>
      <dc:creator>Rob2520</dc:creator>
      <dc:date>2020-09-29T21:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: What capabilities are needed for a non-admin user to update Server Classes and Clients in Settings -&gt; Forwarder Management</title>
      <link>https://community.splunk.com/t5/Security/What-capabilities-are-needed-for-a-non-admin-user-to-update/m-p/459942#M10721</link>
      <description>&lt;P&gt;In order to edit the Server Classes you need to have &lt;STRONG&gt;edit_deployment_server&lt;/STRONG&gt; turned on. This allows creating/editing Server Classes, adding an app to the Server Class, and editing the client list. I did not have to enable &lt;STRONG&gt;edit_deployment_client&lt;/STRONG&gt; for these functions, which is what I want this person to do be able to do, so I have left that off. I also enabled &lt;STRONG&gt;list_deployment_client&lt;/STRONG&gt; and &lt;STRONG&gt;list_deployment_server&lt;/STRONG&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:55:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/What-capabilities-are-needed-for-a-non-admin-user-to-update/m-p/459942#M10721</guid>
      <dc:creator>wrangler2x</dc:creator>
      <dc:date>2020-09-29T21:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: What capabilities are needed for a non-admin user to update Server Classes and Clients in Settings -&gt; Forwarder Management</title>
      <link>https://community.splunk.com/t5/Security/What-capabilities-are-needed-for-a-non-admin-user-to-update/m-p/459943#M10722</link>
      <description>&lt;P&gt;I downvoted this post because not working fully as it should.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Nov 2018 22:15:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/What-capabilities-are-needed-for-a-non-admin-user-to-update/m-p/459943#M10722</guid>
      <dc:creator>wrangler2x</dc:creator>
      <dc:date>2018-11-05T22:15:59Z</dc:date>
    </item>
    <item>
      <title>Re: What capabilities are needed for a non-admin user to update Server Classes and Clients in Settings -&gt; Forwarder Management</title>
      <link>https://community.splunk.com/t5/Security/What-capabilities-are-needed-for-a-non-admin-user-to-update/m-p/459944#M10723</link>
      <description>&lt;P&gt;With the three I mentioned above, he was able to add systems to the whitelist of clients in a Server Class, and he was able to create a new Server Class. However, he was not able to add an application to the new Server Class. I added back in the edit_deployment_client but this made no difference. It throws the following error when you try to save after editing settings and a similar one when trying to add an app:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;User 'cinders' with roles { cinders, user, user_oit_security } cannot write: /nobody/system/serverclass/serverClass:OIT_SC_winevent_index_ADFS:app:OIT_DA_winevent_index_ADFS/restartSplunkWeb { read : [ * ], write : [admin ] }, removable: no
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:55:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/What-capabilities-are-needed-for-a-non-admin-user-to-update/m-p/459944#M10723</guid>
      <dc:creator>wrangler2x</dc:creator>
      <dc:date>2020-09-29T21:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: What capabilities are needed for a non-admin user to update Server Classes and Clients in Settings -&gt; Forwarder Management</title>
      <link>https://community.splunk.com/t5/Security/What-capabilities-are-needed-for-a-non-admin-user-to-update/m-p/459945#M10724</link>
      <description>&lt;P&gt;I have the same issue. It looks like the "edit_deployment_server" capability should confer this permission, but it doesn't.  It looks like this could be worked-around by editing some metadata (which one, I wonder, $SPLUNK_HOME/etc/system/metadata/local.meta?), and adding the proper role at some level. But I don't want to mess with that. I want the capability to work the way you'd expect.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:06:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/What-capabilities-are-needed-for-a-non-admin-user-to-update/m-p/459945#M10724</guid>
      <dc:creator>kscher</dc:creator>
      <dc:date>2020-09-30T00:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: What capabilities are needed for a non-admin user to update Server Classes and Clients in Settings -&gt; Forwarder M</title>
      <link>https://community.splunk.com/t5/Security/What-capabilities-are-needed-for-a-non-admin-user-to-update/m-p/544943#M12162</link>
      <description>&lt;P&gt;Creating a specific role to manage deployment servers&amp;nbsp; serverclass&amp;nbsp; I experienced the same issue with&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;User 'ds_user' with roles { ds_role, ds_user, user } cannot write: /nobody/system/serverclass/serverClass:My_server_class:app:my_app/restartSplunkWeb { read : [ * ], write : [ admin ] }, removable: no&lt;/LI-CODE&gt;&lt;P&gt;The ds_role has the capabilities:&lt;BR /&gt;edit_deployment_client,&lt;BR /&gt;edit_deployment_server,&lt;BR /&gt;list_deployment_client&lt;BR /&gt;list_deployment_server&lt;BR /&gt;&lt;BR /&gt;To be able to add an app to a serverclass the only option was to give the capability&amp;nbsp;admin_all_objects. Which effectively would make&amp;nbsp;ds_role users admins.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To avoid this our workaround was to edit&amp;nbsp;/opt/splunk/etc/system/metadata/local.meta to grant write privilege for ds_role to serverclass objects&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;#On Deployment Server
#/opt/splunk/etc/system/metadata/local.meta
[serverclass]
access = write : [ admin, ds_role ]
export = system&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 14:27:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/What-capabilities-are-needed-for-a-non-admin-user-to-update/m-p/544943#M12162</guid>
      <dc:creator>srauhala_splunk</dc:creator>
      <dc:date>2021-03-23T14:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: What capabilities are needed for a non-admin user to update Server Classes and Clients in Settings -&gt; Forwarder M</title>
      <link>https://community.splunk.com/t5/Security/What-capabilities-are-needed-for-a-non-admin-user-to-update/m-p/596744#M16081</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I wonder if there is an answer to that question ?&lt;/P&gt;&lt;P&gt;I'm stuck on it as well.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ema&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 13:57:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/What-capabilities-are-needed-for-a-non-admin-user-to-update/m-p/596744#M16081</guid>
      <dc:creator>emallinger</dc:creator>
      <dc:date>2022-05-06T13:57:39Z</dc:date>
    </item>
  </channel>
</rss>

