<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Create a read only lookup table in Security</title>
    <link>https://community.splunk.com/t5/Security/Create-a-read-only-lookup-table/m-p/506152#M11583</link>
    <description>&lt;P&gt;I have a user which needs to be able to write one specific lookup table which has to be shared globally. I have to control with the permission settings on the lookup&amp;nbsp; as I have several users/roles where each role has to grant write access to a different lookup table.&lt;BR /&gt;&lt;BR /&gt;What i have observed so far:&lt;BR /&gt;in order to be able to write a lookup table with &lt;STRONG&gt;| outputlookup xxxx.csv,&lt;/STRONG&gt; the user needs the capability&lt;STRONG&gt; &lt;SPAN&gt;output_file&lt;/SPAN&gt;&lt;/STRONG&gt;. This capability is be default granted trough the predefined user role.&lt;BR /&gt;&lt;BR /&gt;With the capability &lt;STRONG&gt;&lt;SPAN&gt;output_file&lt;/SPAN&gt;&lt;/STRONG&gt;, the permission configured in local.meta is ignored,&amp;nbsp; outputlookup writes happily any lookup file, regardless of the permission, even files which don't exist.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What i am missing here?&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jun 2020 13:44:34 GMT</pubDate>
    <dc:creator>FritzWittwer</dc:creator>
    <dc:date>2020-06-25T13:44:34Z</dc:date>
    <item>
      <title>Create a read only lookup table</title>
      <link>https://community.splunk.com/t5/Security/Create-a-read-only-lookup-table/m-p/506152#M11583</link>
      <description>&lt;P&gt;I have a user which needs to be able to write one specific lookup table which has to be shared globally. I have to control with the permission settings on the lookup&amp;nbsp; as I have several users/roles where each role has to grant write access to a different lookup table.&lt;BR /&gt;&lt;BR /&gt;What i have observed so far:&lt;BR /&gt;in order to be able to write a lookup table with &lt;STRONG&gt;| outputlookup xxxx.csv,&lt;/STRONG&gt; the user needs the capability&lt;STRONG&gt; &lt;SPAN&gt;output_file&lt;/SPAN&gt;&lt;/STRONG&gt;. This capability is be default granted trough the predefined user role.&lt;BR /&gt;&lt;BR /&gt;With the capability &lt;STRONG&gt;&lt;SPAN&gt;output_file&lt;/SPAN&gt;&lt;/STRONG&gt;, the permission configured in local.meta is ignored,&amp;nbsp; outputlookup writes happily any lookup file, regardless of the permission, even files which don't exist.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What i am missing here?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 13:44:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Create-a-read-only-lookup-table/m-p/506152#M11583</guid>
      <dc:creator>FritzWittwer</dc:creator>
      <dc:date>2020-06-25T13:44:34Z</dc:date>
    </item>
  </channel>
</rss>

