<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Read-Only role/user in Security</title>
    <link>https://community.splunk.com/t5/Security/Read-Only-role-user/m-p/559860#M12426</link>
    <description>&lt;P&gt;How to make a read-only user/role?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Try to make a new role, but it inherited capabilities from defaults roles. Any suggestions?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 16 Jul 2021 18:46:44 GMT</pubDate>
    <dc:creator>phpguy_80</dc:creator>
    <dc:date>2021-07-16T18:46:44Z</dc:date>
    <item>
      <title>Read-Only role/user</title>
      <link>https://community.splunk.com/t5/Security/Read-Only-role-user/m-p/559860#M12426</link>
      <description>&lt;P&gt;How to make a read-only user/role?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Try to make a new role, but it inherited capabilities from defaults roles. Any suggestions?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jul 2021 18:46:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Read-Only-role-user/m-p/559860#M12426</guid>
      <dc:creator>phpguy_80</dc:creator>
      <dc:date>2021-07-16T18:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: Read-Only role/user</title>
      <link>https://community.splunk.com/t5/Security/Read-Only-role-user/m-p/559888#M12427</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236516"&gt;@phpguy_80&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;it's easy, don't use inheritaton, give to your new user only the requested capabilities without using inheritation.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jul 2021 06:14:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Read-Only-role-user/m-p/559888#M12427</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-07-17T06:14:36Z</dc:date>
    </item>
    <item>
      <title>Re: Read-Only role/user</title>
      <link>https://community.splunk.com/t5/Security/Read-Only-role-user/m-p/559909#M12428</link>
      <description>&lt;P&gt;Oh okay, thought I had to select an existing role, I didn't realize I could just skip that part &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;So now, which capabilities should I select to allow for a read-only role?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jul 2021 16:43:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Read-Only-role-user/m-p/559909#M12428</guid>
      <dc:creator>phpguy_80</dc:creator>
      <dc:date>2021-07-17T16:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: Read-Only role/user</title>
      <link>https://community.splunk.com/t5/Security/Read-Only-role-user/m-p/559916#M12429</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236516"&gt;@phpguy_80&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;when you create a new role, skip the first tab (Inheritance) and go directly the the second one (Capabilities), enabling the ones you need.&lt;/P&gt;&lt;P&gt;Remember to enable Indexes otherwise this role will not see anything!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jul 2021 16:42:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Read-Only-role-user/m-p/559916#M12429</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-07-17T16:42:54Z</dc:date>
    </item>
    <item>
      <title>Re: Read-Only role/user</title>
      <link>https://community.splunk.com/t5/Security/Read-Only-role-user/m-p/559928#M12430</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236516"&gt;@phpguy_80&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;under capabilities tab you can select 'search' for read only to selected indexes. 'schedule_search' if you wish allow the user&amp;nbsp; to schedule searches. Created role shall be assigned to user you wish to allow read permissions.&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;An upvote would be appreciated if this reply helps!&lt;/P&gt;</description>
      <pubDate>Sun, 18 Jul 2021 02:28:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Read-Only-role-user/m-p/559928#M12430</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-07-18T02:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: Read-Only role/user</title>
      <link>https://community.splunk.com/t5/Security/Read-Only-role-user/m-p/559929#M12431</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236516"&gt;@phpguy_80&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;in few words, Splunk don't permit to modify indexed data, so you have only to disable (or not enable) capabilities as knowledge objects creation or modify and log delete.&lt;/P&gt;&lt;P&gt;So you could start to enable:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;change_own_password&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;rtsearch (only if user must be enabled to Real Time Searches)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;search&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;I don't know what your Apps contain, so e.g. if you have a dashboard that lists Deployment Clients using a REST command, you have to enable a specific feature as "rest_properties_get".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As I said, remember to enable the correct Indexes.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Jul 2021 05:50:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Read-Only-role-user/m-p/559929#M12431</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-07-18T05:50:36Z</dc:date>
    </item>
  </channel>
</rss>

