<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Permissions to delete searches in Splunk 6.1.1 in Security</title>
    <link>https://community.splunk.com/t5/Security/Permissions-to-delete-searches-in-Splunk-6-1-1/m-p/185400#M14770</link>
    <description>&lt;P&gt;okay, this question can be read both ways. The search command &lt;CODE&gt;delete&lt;/CODE&gt; is no longer granted by default (this is the &lt;CODE&gt;delete_by_keyword&lt;/CODE&gt; capability btw) and must be assigned, also &lt;CODE&gt;delete&lt;/CODE&gt; does not actually delete raw data; it masks the data from showing up in search results. &lt;/P&gt;

&lt;P&gt;To delete searches as &lt;STRONG&gt;local admin&lt;/STRONG&gt;, using the Job monitor for example, one does not need any special capability.&lt;/P&gt;

&lt;P&gt;Maybe the problem it the search head pooling over NFS, try the OS way from the docs to delete those searches &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.1/Knowledge/ManagejobsfromtheOS"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.1/Knowledge/ManagejobsfromtheOS&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 03 Jun 2014 05:57:49 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2014-06-03T05:57:49Z</dc:date>
    <item>
      <title>Permissions to delete searches in Splunk 6.1.1</title>
      <link>https://community.splunk.com/t5/Security/Permissions-to-delete-searches-in-Splunk-6-1-1/m-p/185397#M14767</link>
      <description>&lt;P&gt;Recently we upgraded to 6.1.1 and I've noticed that users with admin access no longer can delete searches.   What permission is needed for this?&lt;/P&gt;

&lt;P&gt;It shouldn't be relevant, but we are using search head pooling over NFS.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2014 14:10:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Permissions-to-delete-searches-in-Splunk-6-1-1/m-p/185397#M14767</guid>
      <dc:creator>adylent</dc:creator>
      <dc:date>2014-06-02T14:10:52Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions to delete searches in Splunk 6.1.1</title>
      <link>https://community.splunk.com/t5/Security/Permissions-to-delete-searches-in-Splunk-6-1-1/m-p/185398#M14768</link>
      <description>&lt;P&gt;Hi adylent,&lt;/P&gt;

&lt;P&gt;Just had this problem last week, add the &lt;CODE&gt;can delete&lt;/CODE&gt; capability to the admin and you're done.&lt;/P&gt;

&lt;P&gt;Cheers, MuS&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2014 16:23:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Permissions-to-delete-searches-in-Splunk-6-1-1/m-p/185398#M14768</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-06-02T16:23:41Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions to delete searches in Splunk 6.1.1</title>
      <link>https://community.splunk.com/t5/Security/Permissions-to-delete-searches-in-Splunk-6-1-1/m-p/185399#M14769</link>
      <description>&lt;P&gt;Isn't that capability designed to give the ability to delete data from Splunk using the "delete" command? Per Splunk best practices, this capability should not normally be granted to any users, but instead should only temporarily be granted when specific data needs to be deleted.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2014 17:33:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Permissions-to-delete-searches-in-Splunk-6-1-1/m-p/185399#M14769</guid>
      <dc:creator>rtadams89</dc:creator>
      <dc:date>2014-06-02T17:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions to delete searches in Splunk 6.1.1</title>
      <link>https://community.splunk.com/t5/Security/Permissions-to-delete-searches-in-Splunk-6-1-1/m-p/185400#M14770</link>
      <description>&lt;P&gt;okay, this question can be read both ways. The search command &lt;CODE&gt;delete&lt;/CODE&gt; is no longer granted by default (this is the &lt;CODE&gt;delete_by_keyword&lt;/CODE&gt; capability btw) and must be assigned, also &lt;CODE&gt;delete&lt;/CODE&gt; does not actually delete raw data; it masks the data from showing up in search results. &lt;/P&gt;

&lt;P&gt;To delete searches as &lt;STRONG&gt;local admin&lt;/STRONG&gt;, using the Job monitor for example, one does not need any special capability.&lt;/P&gt;

&lt;P&gt;Maybe the problem it the search head pooling over NFS, try the OS way from the docs to delete those searches &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.1/Knowledge/ManagejobsfromtheOS"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.1/Knowledge/ManagejobsfromtheOS&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2014 05:57:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Permissions-to-delete-searches-in-Splunk-6-1-1/m-p/185400#M14770</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-06-03T05:57:49Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions to delete searches in Splunk 6.1.1</title>
      <link>https://community.splunk.com/t5/Security/Permissions-to-delete-searches-in-Splunk-6-1-1/m-p/185401#M14771</link>
      <description>&lt;P&gt;To anyone trying to add permissions to a user, you'll have to go to &lt;CODE&gt;Settings -&amp;gt; Access Controls&lt;/CODE&gt; and select a user. &lt;CODE&gt;can_delete&lt;/CODE&gt; is here.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2016 11:26:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Permissions-to-delete-searches-in-Splunk-6-1-1/m-p/185401#M14771</guid>
      <dc:creator>bhawkins1</dc:creator>
      <dc:date>2016-12-22T11:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions to delete searches in Splunk 6.1.1</title>
      <link>https://community.splunk.com/t5/Security/Permissions-to-delete-searches-in-Splunk-6-1-1/m-p/574687#M15706</link>
      <description>&lt;P&gt;In Splunk&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;go to Settings -&amp;gt; Users&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Under actions TAB click on edit and assign a role : can_delete&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;please check below SS.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-11-12 at 10.32.08 AM.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16835i3BE5A722C2B166E3/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2021-11-12 at 10.32.08 AM.png" alt="Screenshot 2021-11-12 at 10.32.08 AM.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 05:06:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Permissions-to-delete-searches-in-Splunk-6-1-1/m-p/574687#M15706</guid>
      <dc:creator>erritesh17</dc:creator>
      <dc:date>2021-11-12T05:06:09Z</dc:date>
    </item>
  </channel>
</rss>

