<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Create new role with almost admin capabilities in Security</title>
    <link>https://community.splunk.com/t5/Security/Create-new-role-with-almost-admin-capabilities/m-p/191145#M5632</link>
    <description>&lt;P&gt;The word "admin" is anathema to our IA people. As a result, even though I am the only Splunk developer, I am not permitted to have "admin" privileges. So I have created a new role named "manager". But this role does not have all the permissions I need. What I need is to have full access to all the menu options in the attached screenshot. &lt;/P&gt;

&lt;P&gt;I do not get Data inputs and Indexes, though if I copy and paste into the address bar I can get to these pages. But I don't have the capability to full app management.&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://answers.splunk.com//storage/ManagerCapabilities.png" alt="alt text" /&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Mar 2014 16:30:40 GMT</pubDate>
    <dc:creator>kmattern</dc:creator>
    <dc:date>2014-03-17T16:30:40Z</dc:date>
    <item>
      <title>Create new role with almost admin capabilities</title>
      <link>https://community.splunk.com/t5/Security/Create-new-role-with-almost-admin-capabilities/m-p/191145#M5632</link>
      <description>&lt;P&gt;The word "admin" is anathema to our IA people. As a result, even though I am the only Splunk developer, I am not permitted to have "admin" privileges. So I have created a new role named "manager". But this role does not have all the permissions I need. What I need is to have full access to all the menu options in the attached screenshot. &lt;/P&gt;

&lt;P&gt;I do not get Data inputs and Indexes, though if I copy and paste into the address bar I can get to these pages. But I don't have the capability to full app management.&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://answers.splunk.com//storage/ManagerCapabilities.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2014 16:30:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Create-new-role-with-almost-admin-capabilities/m-p/191145#M5632</guid>
      <dc:creator>kmattern</dc:creator>
      <dc:date>2014-03-17T16:30:40Z</dc:date>
    </item>
    <item>
      <title>Re: Create new role with almost admin capabilities</title>
      <link>https://community.splunk.com/t5/Security/Create-new-role-with-almost-admin-capabilities/m-p/191146#M5633</link>
      <description>&lt;P&gt;Add "admin_all_object" capability to manager role.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:09:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Create-new-role-with-almost-admin-capabilities/m-p/191146#M5633</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2020-09-28T16:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: Create new role with almost admin capabilities</title>
      <link>https://community.splunk.com/t5/Security/Create-new-role-with-almost-admin-capabilities/m-p/191147#M5634</link>
      <description>&lt;P&gt;But that appears to give admin capabilities to everything. that won't work.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2014 17:31:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Create-new-role-with-almost-admin-capabilities/m-p/191147#M5634</guid>
      <dc:creator>kmattern</dc:creator>
      <dc:date>2014-03-17T17:31:53Z</dc:date>
    </item>
    <item>
      <title>Re: Create new role with almost admin capabilities</title>
      <link>https://community.splunk.com/t5/Security/Create-new-role-with-almost-admin-capabilities/m-p/191148#M5635</link>
      <description>&lt;P&gt;I couldn't find any other capabilities which will allow to edit/view data inputs from settings. Updating data inputs and indexes are the admin activities, but Splunk doesn't have capabilities defined for them individually.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2014 19:30:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Create-new-role-with-almost-admin-capabilities/m-p/191148#M5635</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-03-17T19:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: Create new role with almost admin capabilities</title>
      <link>https://community.splunk.com/t5/Security/Create-new-role-with-almost-admin-capabilities/m-p/191149#M5636</link>
      <description>&lt;P&gt;Alternatively, just edit the .conf files manually (or on a deployment server and push them out it you have a distributed environment). Then you can control the access to the .conf files by OS level file permissions.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2014 22:19:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Create-new-role-with-almost-admin-capabilities/m-p/191149#M5636</guid>
      <dc:creator>rtadams89</dc:creator>
      <dc:date>2014-03-17T22:19:21Z</dc:date>
    </item>
    <item>
      <title>Re: Create new role with almost admin capabilities</title>
      <link>https://community.splunk.com/t5/Security/Create-new-role-with-almost-admin-capabilities/m-p/191150#M5637</link>
      <description>&lt;P&gt;I'm not allowed to have any OS level capabilities. I've been doing this kind of Splunk work for almost five years and this is the first time I have been shut down. Don't work for the Department of Defense if you want to work on Splunk.&lt;/P&gt;

&lt;P&gt;The problem isn't Splunk admin capabilities, it is the term "admin" that IA doesn't like! They won't bother to learn what the Splunk admin role is, only that it is "Administrative in nature and therefore restriced." &lt;/P&gt;

&lt;P&gt;Von Schiller said it best, "Against stupidity the very gods themselves contend in vein."&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2014 13:40:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Create-new-role-with-almost-admin-capabilities/m-p/191150#M5637</guid>
      <dc:creator>kmattern</dc:creator>
      <dc:date>2014-03-18T13:40:13Z</dc:date>
    </item>
  </channel>
</rss>

