<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk free and capability in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-free-and-capability/m-p/350095#M12461</link>
    <description>&lt;P&gt;I didn't create a user, as you said it is the user (no-user) of the Splunk-free version.&lt;BR /&gt;
I modified the license from trial to free.&lt;/P&gt;

&lt;P&gt;In he Admin Manual, about free version, there is not a description of the enabled capabilities.&lt;BR /&gt;
I expected that even if there is not role management the events access/deletion could be managed.&lt;/P&gt;</description>
    <pubDate>Thu, 03 Aug 2017 15:14:50 GMT</pubDate>
    <dc:creator>Alive77</dc:creator>
    <dc:date>2017-08-03T15:14:50Z</dc:date>
    <item>
      <title>Splunk free and capability</title>
      <link>https://community.splunk.com/t5/Security/Splunk-free-and-capability/m-p/350092#M12458</link>
      <description>&lt;P&gt;I just installed Splunk 6.6.2 free.&lt;BR /&gt;
Is there a way to modify free user capability, in my situation I would like disable delete capability.&lt;/P&gt;

&lt;P&gt;At this moment, I create a new user and i'm able to delete events using CLI, with command:&lt;/P&gt;

&lt;P&gt;index= somethingtodelete | delete&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 13:47:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-free-and-capability/m-p/350092#M12458</guid>
      <dc:creator>Alive77</dc:creator>
      <dc:date>2017-08-03T13:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk free and capability</title>
      <link>https://community.splunk.com/t5/Security/Splunk-free-and-capability/m-p/350093#M12459</link>
      <description>&lt;P&gt;Hi there, edit the capabilities of the role related to that user or check if role user ineherits can_delete capability from other role.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 14:40:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-free-and-capability/m-p/350093#M12459</guid>
      <dc:creator>alemarzu</dc:creator>
      <dc:date>2017-08-03T14:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk free and capability</title>
      <link>https://community.splunk.com/t5/Security/Splunk-free-and-capability/m-p/350094#M12460</link>
      <description>&lt;P&gt;If you are using the free Enterprise trial, then check alemarzu's suggestion.&lt;/P&gt;

&lt;P&gt;If you are using Splunk Free, then there is no user or role management (see &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.2/Admin/MoreaboutSplunkFree"&gt;About Splunk Free&lt;/A&gt; in the &lt;EM&gt;Admin Manual&lt;/EM&gt;).&lt;/P&gt;

&lt;P&gt;The fact that you could create a user account suggests that you are using the 60-day free Enterprise trial, which is what you get when you first download and install Splunk Enterprise.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 14:55:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-free-and-capability/m-p/350094#M12460</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2017-08-03T14:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk free and capability</title>
      <link>https://community.splunk.com/t5/Security/Splunk-free-and-capability/m-p/350095#M12461</link>
      <description>&lt;P&gt;I didn't create a user, as you said it is the user (no-user) of the Splunk-free version.&lt;BR /&gt;
I modified the license from trial to free.&lt;/P&gt;

&lt;P&gt;In he Admin Manual, about free version, there is not a description of the enabled capabilities.&lt;BR /&gt;
I expected that even if there is not role management the events access/deletion could be managed.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 15:14:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-free-and-capability/m-p/350095#M12461</guid>
      <dc:creator>Alive77</dc:creator>
      <dc:date>2017-08-03T15:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk free and capability</title>
      <link>https://community.splunk.com/t5/Security/Splunk-free-and-capability/m-p/350096#M12462</link>
      <description>&lt;P&gt;Quoting from that topic: "All accesses are treated as equivalent to the admin user. There is only one role (admin), and it is not configurable. You cannot add more roles or create user accounts." The admin role has all the capabilities listed &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.2/Security/Rolesandcapabilities"&gt;here&lt;/A&gt;, and you cannot configure or manage them under the free license.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 15:44:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-free-and-capability/m-p/350096#M12462</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2017-08-03T15:44:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk free and capability</title>
      <link>https://community.splunk.com/t5/Security/Splunk-free-and-capability/m-p/350097#M12463</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/12657"&gt;@ChrisG&lt;/a&gt; that's not true. According the manual, Admin has not the delete_by_keyword capability. In Splunk Free this capability is active.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:14:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-free-and-capability/m-p/350097#M12463</guid>
      <dc:creator>Alive77</dc:creator>
      <dc:date>2020-09-29T15:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk free and capability</title>
      <link>https://community.splunk.com/t5/Security/Splunk-free-and-capability/m-p/350098#M12464</link>
      <description>&lt;P&gt;Good correction, thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2017 15:32:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-free-and-capability/m-p/350098#M12464</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2017-08-04T15:32:31Z</dc:date>
    </item>
  </channel>
</rss>

