<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Role Capability to Query Lookup in Security</title>
    <link>https://community.splunk.com/t5/Security/Role-Capability-to-Query-Lookup/m-p/544550#M12158</link>
    <description>&lt;P&gt;I am the admin who has access to that app.&amp;nbsp; The issue is that we do NOT want to give read access to the app for new custom role, but we want them to be able to query the Lookup.&lt;/P&gt;</description>
    <pubDate>Fri, 19 Mar 2021 17:19:32 GMT</pubDate>
    <dc:creator>dglass0215</dc:creator>
    <dc:date>2021-03-19T17:19:32Z</dc:date>
    <item>
      <title>Role Capability to Query Lookup</title>
      <link>https://community.splunk.com/t5/Security/Role-Capability-to-Query-Lookup/m-p/544531#M12153</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to figure out which Role Capability controls being able to use a lookup in a query.&amp;nbsp; If I select all the capabilities then the role certainly can query a lookup.&amp;nbsp; However if I select only the capabilities that I want the role to have, they lose the ability to query the lookup.&amp;nbsp; Looking at the documentation (&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.2/Security/Rolesandcapabilities" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.2/Security/Rolesandcapabilities&lt;/A&gt;) it does not specify which capability allows for the querying of a lookup.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 15:48:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Role-Capability-to-Query-Lookup/m-p/544531#M12153</guid>
      <dc:creator>dglass0215</dc:creator>
      <dc:date>2021-03-19T15:48:23Z</dc:date>
    </item>
    <item>
      <title>Re: Role Capability to Query Lookup</title>
      <link>https://community.splunk.com/t5/Security/Role-Capability-to-Query-Lookup/m-p/544532#M12154</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/117218"&gt;@dglass0215&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;It depends on what permission you will give to the lookup file. If you give only admin and power user roles to read and write the lookup. Then the user needs a power user role to access the lookup files.&lt;/P&gt;&lt;P&gt;But if you give read access for everyone. Then user role will be sufficient to access the lookup in the query.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 15:53:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Role-Capability-to-Query-Lookup/m-p/544532#M12154</guid>
      <dc:creator>Vardhan</dc:creator>
      <dc:date>2021-03-19T15:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: Role Capability to Query Lookup</title>
      <link>https://community.splunk.com/t5/Security/Role-Capability-to-Query-Lookup/m-p/544533#M12155</link>
      <description>&lt;P&gt;The lookup has Read permission for Everyone (including the custom Role I am having issues with).&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 16:07:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Role-Capability-to-Query-Lookup/m-p/544533#M12155</guid>
      <dc:creator>dglass0215</dc:creator>
      <dc:date>2021-03-19T16:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: Role Capability to Query Lookup</title>
      <link>https://community.splunk.com/t5/Security/Role-Capability-to-Query-Lookup/m-p/544536#M12156</link>
      <description>&lt;P&gt;I think I found the problem but I do not know the solution.&amp;nbsp; While I have given read permission to the lookup specifically for the custom Role, the role does not have permission to the app that created the lookup.&amp;nbsp; Not sure what I can do.&amp;nbsp; I definitely DO NOT want the role to have access to the app but I need the role to be able to query the lookup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 16:22:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Role-Capability-to-Query-Lookup/m-p/544536#M12156</guid>
      <dc:creator>dglass0215</dc:creator>
      <dc:date>2021-03-19T16:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: Role Capability to Query Lookup</title>
      <link>https://community.splunk.com/t5/Security/Role-Capability-to-Query-Lookup/m-p/544549#M12157</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/117218"&gt;@dglass0215&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ask someone who has access to that app to provide read permission to your custom role.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 17:15:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Role-Capability-to-Query-Lookup/m-p/544549#M12157</guid>
      <dc:creator>Vardhan</dc:creator>
      <dc:date>2021-03-19T17:15:15Z</dc:date>
    </item>
    <item>
      <title>Re: Role Capability to Query Lookup</title>
      <link>https://community.splunk.com/t5/Security/Role-Capability-to-Query-Lookup/m-p/544550#M12158</link>
      <description>&lt;P&gt;I am the admin who has access to that app.&amp;nbsp; The issue is that we do NOT want to give read access to the app for new custom role, but we want them to be able to query the Lookup.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 17:19:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Role-Capability-to-Query-Lookup/m-p/544550#M12158</guid>
      <dc:creator>dglass0215</dc:creator>
      <dc:date>2021-03-19T17:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: Role Capability to Query Lookup</title>
      <link>https://community.splunk.com/t5/Security/Role-Capability-to-Query-Lookup/m-p/544569#M12159</link>
      <description>&lt;P&gt;So, you should move the lookup to an app that both users have access. Your lookup level permissions will prevent unwanted access.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 20:14:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Role-Capability-to-Query-Lookup/m-p/544569#M12159</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-03-19T20:14:57Z</dc:date>
    </item>
  </channel>
</rss>

