<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: capability admin all objects in Security</title>
    <link>https://community.splunk.com/t5/Security/capability-admin-all-objects/m-p/465327#M10829</link>
    <description>&lt;P&gt;Of course, with respect to that point we will make the pertinent modifications, but the requirement that we have is how to limit that the programmed searches do not exceed 60 minutes of execution?&lt;/P&gt;</description>
    <pubDate>Wed, 12 Feb 2020 16:36:25 GMT</pubDate>
    <dc:creator>efaundez</dc:creator>
    <dc:date>2020-02-12T16:36:25Z</dc:date>
    <item>
      <title>capability admin all objects</title>
      <link>https://community.splunk.com/t5/Security/capability-admin-all-objects/m-p/465322#M10824</link>
      <description>&lt;P&gt;good afternoon&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&amp;nbsp; I have the following question, there are currently roles in our cluster that have the following restriction srchMaxTime = 3600, but it is validated that certain users are searching for more than 1 hour and I ask if this is due to the cability "admin all object".&lt;/P&gt;

&lt;P&gt;any help is appreciated&lt;/P&gt;

&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 20:02:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/capability-admin-all-objects/m-p/465322#M10824</guid>
      <dc:creator>efaundez</dc:creator>
      <dc:date>2020-02-11T20:02:12Z</dc:date>
    </item>
    <item>
      <title>Re: capability admin all objects</title>
      <link>https://community.splunk.com/t5/Security/capability-admin-all-objects/m-p/465323#M10825</link>
      <description>&lt;P&gt;admin_all_objects&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Lets the user access and modify any object in the system regardless of any restrictions set in the objects. For example user objects, search jobs, reports, and knowledge objects. Lets the user bypass any ACL restrictions, much the way root access in a *nix environment does.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.1/Security/Rolesandcapabilities" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.1/Security/Rolesandcapabilities&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;if you have admin_all_objects all restrictions can be disabled.&lt;BR /&gt;
Only trusted admins should have that capability&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:10:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/capability-admin-all-objects/m-p/465323#M10825</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2020-09-30T04:10:21Z</dc:date>
    </item>
    <item>
      <title>Re: capability admin all objects</title>
      <link>https://community.splunk.com/t5/Security/capability-admin-all-objects/m-p/465324#M10826</link>
      <description>&lt;P&gt;Good afternoon&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&amp;nbsp; Thanks for the answer, but I have performed tests on the servers with a user who has admin_all_object and the ad-hoc searches are limited in the same way, for my example leave the parameter srchMaxTime = 60 and the query ended, but I am validating if the searches programmed are also limited by this parameter.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:10:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/capability-admin-all-objects/m-p/465324#M10826</guid>
      <dc:creator>efaundez</dc:creator>
      <dc:date>2020-09-30T04:10:57Z</dc:date>
    </item>
    <item>
      <title>Re: capability admin all objects</title>
      <link>https://community.splunk.com/t5/Security/capability-admin-all-objects/m-p/465325#M10827</link>
      <description>&lt;P&gt;Reports and searches can be configured to run with the role of either the user who created them, or the user who runs them.&lt;/P&gt;

&lt;P&gt;If a user with higher capabilities creates a search, but is run by a user with lesser role, the search may be configured to run with the higher capabilities.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 16:33:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/capability-admin-all-objects/m-p/465325#M10827</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2020-02-12T16:33:40Z</dc:date>
    </item>
    <item>
      <title>Re: capability admin all objects</title>
      <link>https://community.splunk.com/t5/Security/capability-admin-all-objects/m-p/465326#M10828</link>
      <description>&lt;P&gt;Also - its worth noting that if someone has admin_all_objects, it means they can change their own capabilities.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:11:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/capability-admin-all-objects/m-p/465326#M10828</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2020-09-30T04:11:00Z</dc:date>
    </item>
    <item>
      <title>Re: capability admin all objects</title>
      <link>https://community.splunk.com/t5/Security/capability-admin-all-objects/m-p/465327#M10829</link>
      <description>&lt;P&gt;Of course, with respect to that point we will make the pertinent modifications, but the requirement that we have is how to limit that the programmed searches do not exceed 60 minutes of execution?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 16:36:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/capability-admin-all-objects/m-p/465327#M10829</guid>
      <dc:creator>efaundez</dc:creator>
      <dc:date>2020-02-12T16:36:25Z</dc:date>
    </item>
  </channel>
</rss>

