<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: permissions question in Security</title>
    <link>https://community.splunk.com/t5/Security/permissions-question/m-p/179047#M5317</link>
    <description>&lt;P&gt;Does the view belong to the user who marked it private?  If they didnt create the view they wont see it after they mark it private because it's private to owner not the person who marks it private.&lt;/P&gt;</description>
    <pubDate>Tue, 27 May 2014 13:41:19 GMT</pubDate>
    <dc:creator>jkat54</dc:creator>
    <dc:date>2014-05-27T13:41:19Z</dc:date>
    <item>
      <title>permissions question</title>
      <link>https://community.splunk.com/t5/Security/permissions-question/m-p/179046#M5316</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Once a view is created and made private, does a power user have the ability to change the permissions?  I have some users who can't change permissions after saving the original item as private.  &lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2014 13:03:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/permissions-question/m-p/179046#M5316</guid>
      <dc:creator>a212830</dc:creator>
      <dc:date>2014-05-27T13:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: permissions question</title>
      <link>https://community.splunk.com/t5/Security/permissions-question/m-p/179047#M5317</link>
      <description>&lt;P&gt;Does the view belong to the user who marked it private?  If they didnt create the view they wont see it after they mark it private because it's private to owner not the person who marks it private.&lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2014 13:41:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/permissions-question/m-p/179047#M5317</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2014-05-27T13:41:19Z</dc:date>
    </item>
    <item>
      <title>Re: permissions question</title>
      <link>https://community.splunk.com/t5/Security/permissions-question/m-p/179048#M5318</link>
      <description>&lt;P&gt;He is listed as the owner, but Permissions link isn't there.&lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2014 14:02:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/permissions-question/m-p/179048#M5318</guid>
      <dc:creator>a212830</dc:creator>
      <dc:date>2014-05-27T14:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: permissions question</title>
      <link>https://community.splunk.com/t5/Security/permissions-question/m-p/179049#M5319</link>
      <description>&lt;P&gt;My guess it's a file permissions issue:&lt;/P&gt;

&lt;P&gt;If splunkd was running as root when the view was created.  That would make the .conf file owned by root.  Then if the current owner of splunkd has changed to something like splunk_daemon_service_account, splunkd wouldnt be able to edit the file.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:43:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/permissions-question/m-p/179049#M5319</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2020-09-28T16:43:54Z</dc:date>
    </item>
    <item>
      <title>Re: permissions question</title>
      <link>https://community.splunk.com/t5/Security/permissions-question/m-p/179050#M5320</link>
      <description>&lt;P&gt;I think this would reveal the permissions issue if it existed:   index=_internal  ( source="*splunkd.log" )  ( log_level="ERROR" )   &lt;/P&gt;

&lt;P&gt;You should see something like "file not found", "permission denied" etc.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:43:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/permissions-question/m-p/179050#M5320</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2020-09-28T16:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: permissions question</title>
      <link>https://community.splunk.com/t5/Security/permissions-question/m-p/179051#M5321</link>
      <description>&lt;P&gt;Roles are implemented within Splunk with different capabilities : &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.1/Security/Rolesandcapabilities#List_of_available_capabilities"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.1/Security/Rolesandcapabilities#List_of_available_capabilities&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If the power user you're talking about has the proper capability, (s)he'll be able to change Permissions.&lt;/P&gt;

&lt;P&gt;Another possibility is to do that directly by editing the .conf files within the user's directory.&lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2014 15:30:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/permissions-question/m-p/179051#M5321</guid>
      <dc:creator>ofrachon</dc:creator>
      <dc:date>2014-05-27T15:30:44Z</dc:date>
    </item>
    <item>
      <title>Re: permissions question</title>
      <link>https://community.splunk.com/t5/Security/permissions-question/m-p/179052#M5322</link>
      <description>&lt;P&gt;Bingo.  We implemented new roles with 6.1.1 and this user was put in a different role.  All set. Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2014 16:51:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/permissions-question/m-p/179052#M5322</guid>
      <dc:creator>a212830</dc:creator>
      <dc:date>2014-05-27T16:51:43Z</dc:date>
    </item>
  </channel>
</rss>

