<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk access delegation/roles in Security</title>
    <link>https://community.splunk.com/t5/Security/splunk-access-delegation-roles/m-p/94248#M3120</link>
    <description>&lt;P&gt;Just tried the same without success (version 4.1.7). Have you considered opening a case ?&lt;/P&gt;

&lt;P&gt;I found a solution that might help. You can overwrite the admin role in local\autorize.conf and reduce the number of capabilities. The you can define a new "myadmin" role with all capabilities. But I don't know, how that works out with updates.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Mar 2011 23:02:30 GMT</pubDate>
    <dc:creator>wollinet</dc:creator>
    <dc:date>2011-03-09T23:02:30Z</dc:date>
    <item>
      <title>splunk access delegation/roles</title>
      <link>https://community.splunk.com/t5/Security/splunk-access-delegation-roles/m-p/94247#M3119</link>
      <description>&lt;P&gt;I'm trying to set up a role in one of our splunk servers (running 4.1.5 on a 64 bit redhat linux 5 machine).  What I really want to do is create a role that has almost all admin capabilities except the ability to delete data and modify roles.  This role should be able to create indexes and start/stop splunk.&lt;/P&gt;

&lt;P&gt;I see that there are some capabilities that seem to grant this (like restart_splunkd).  However, while I can these capabilities to a role, I noticed that all roles except the built-in "admin" role are missing certain sections in the manager section.  Logging in with a user that has the admin role, I see the following on the right column under "System configurations"&lt;/P&gt;

&lt;PRE&gt;
-System settings
-Server controls
-License
-Data inputs
-Forwarding and receiving
-Indexes
-Access controls
-Distributed search
-Deployment
-User options
&lt;/PRE&gt;

&lt;P&gt;However, if I grant a role the ability to restart splunk, and place a user in that role, logging into the manager section with that user only shows one item on the left under "System Configurations", which is the "User options" section.&lt;/P&gt;

&lt;P&gt;I've even gone as far as cloning the "admin" role and trying to log in with that newly (and unmodified after the clone) role, and I still do not see the full list of options in the Manager under "System configurations".&lt;/P&gt;

&lt;P&gt;So, since I figure I'm missing something very obvious, can someone either point me in the right direction, or confirm that what i'm trying to do is just not possible?
-Joseph&lt;/P&gt;</description>
      <pubDate>Thu, 25 Nov 2010 00:16:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/splunk-access-delegation-roles/m-p/94247#M3119</guid>
      <dc:creator>jbanda</dc:creator>
      <dc:date>2010-11-25T00:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: splunk access delegation/roles</title>
      <link>https://community.splunk.com/t5/Security/splunk-access-delegation-roles/m-p/94248#M3120</link>
      <description>&lt;P&gt;Just tried the same without success (version 4.1.7). Have you considered opening a case ?&lt;/P&gt;

&lt;P&gt;I found a solution that might help. You can overwrite the admin role in local\autorize.conf and reduce the number of capabilities. The you can define a new "myadmin" role with all capabilities. But I don't know, how that works out with updates.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2011 23:02:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/splunk-access-delegation-roles/m-p/94248#M3120</guid>
      <dc:creator>wollinet</dc:creator>
      <dc:date>2011-03-09T23:02:30Z</dc:date>
    </item>
  </channel>
</rss>

