<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Admins can't see private searches/reports/alerts in Security</title>
    <link>https://community.splunk.com/t5/Security/Admins-can-t-see-private-searches-reports-alerts/m-p/242871#M6771</link>
    <description>&lt;P&gt;Seems to work fine. Thanks a lot mate &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Jan 2016 10:41:29 GMT</pubDate>
    <dc:creator>alekksi</dc:creator>
    <dc:date>2016-01-26T10:41:29Z</dc:date>
    <item>
      <title>Admins can't see private searches/reports/alerts</title>
      <link>https://community.splunk.com/t5/Security/Admins-can-t-see-private-searches-reports-alerts/m-p/242864#M6764</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;

&lt;P&gt;As an admin user, I am unable to see private dashboards and searches saved by some users. I know that a number of these exist, including some from users who have now left the company. What is the easiest way of cleaning up these objects?  &lt;/P&gt;

&lt;P&gt;I can confirm that the admin role has the 'admin_all_objects' capability.  &lt;/P&gt;

&lt;P&gt;Thanks in advance,&lt;BR /&gt;
Alex&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:30:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Admins-can-t-see-private-searches-reports-alerts/m-p/242864#M6764</guid>
      <dc:creator>alekksi</dc:creator>
      <dc:date>2020-09-29T08:30:57Z</dc:date>
    </item>
    <item>
      <title>Re: Admins can't see private searches/reports/alerts</title>
      <link>https://community.splunk.com/t5/Security/Admins-can-t-see-private-searches-reports-alerts/m-p/242865#M6765</link>
      <description>&lt;P&gt;Hi alekksi&lt;/P&gt;

&lt;P&gt;Verify if in your splunk instance Admin Role has all the following selected capabilities &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;accelerate_datamodel
admin_all_objects
change_authentication
edit_deployment_client
edit_deployment_server
edit_dist_peer
edit_forwarders
edit_httpauths
edit_input_defaults
edit_monitor
edit_roles
edit_scripted
edit_search_head_clustering
edit_search_scheduler
edit_search_server
edit_server
edit_splunktcp
edit_splunktcp_ssl
edit_tcp
edit_token_http
edit_udp
edit_user
edit_view_html
edit_web_settings
edit_win_admon
edit_win_eventlogs
edit_win_perfmon
edit_win_regmon
edit_win_wmiconf
get_diag
indexes_edit
license_edit
license_tab
list_deployment_client
list_deployment_server
list_forwarders
list_httpauths
list_pdfserver
list_search_head_clustering
list_search_scheduler
list_win_localavailablelogs
rest_apps_management
restart_splunkd
run_debug_commands
web_debug
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Verify also imported capabilities&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;accelerate_search
change_own_password
edit_sourcetypes
embed_report
get_metadata
get_typeahead
input_file
list_inputs
output_file
pattern_detect
request_remote_tok
rest_apps_view
rest_properties_get
rest_properties_set
rtsearch
schedule_rtsearch
schedule_search
search
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 25 Jan 2016 11:56:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Admins-can-t-see-private-searches-reports-alerts/m-p/242865#M6765</guid>
      <dc:creator>chimell</dc:creator>
      <dc:date>2016-01-25T11:56:36Z</dc:date>
    </item>
    <item>
      <title>Re: Admins can't see private searches/reports/alerts</title>
      <link>https://community.splunk.com/t5/Security/Admins-can-t-see-private-searches-reports-alerts/m-p/242866#M6766</link>
      <description>&lt;P&gt;I can verify that, of the top list, the following are missing:&lt;BR /&gt;
edit_search_scheduler (doesn't exist in 6.2.3, the current version we're on -- should be moving to 6.3.x in a month or so)&lt;BR /&gt;
edit_token_http&lt;BR /&gt;
edit_win_admon&lt;BR /&gt;
edit_win_eventlogs&lt;BR /&gt;
edit_win_perfmon&lt;BR /&gt;
edit_win_regmon&lt;BR /&gt;
edit_win_wmiconf&lt;BR /&gt;
list_pdfserver&lt;BR /&gt;
list_search_scheduler&lt;BR /&gt;
list_win_localavailablelogs&lt;BR /&gt;
web_debug (doesn't exist in 6.2.3)&lt;/P&gt;

&lt;P&gt;Of the bottom list, I'm not sure exactly how to get most of these are turned on -- only schedule_rtsearch is appearing -- but I'm sure that a number of these are turned on for admin users.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:31:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Admins-can-t-see-private-searches-reports-alerts/m-p/242866#M6766</guid>
      <dc:creator>alekksi</dc:creator>
      <dc:date>2020-09-29T08:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: Admins can't see private searches/reports/alerts</title>
      <link>https://community.splunk.com/t5/Security/Admins-can-t-see-private-searches-reports-alerts/m-p/242867#M6767</link>
      <description>&lt;P&gt;my Splunk instance is version 6.3.2 then it is possible that we have difference.Just add the capabilities which are absent to complete the list and re test&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2016 13:11:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Admins-can-t-see-private-searches-reports-alerts/m-p/242867#M6767</guid>
      <dc:creator>chimell</dc:creator>
      <dc:date>2016-01-25T13:11:46Z</dc:date>
    </item>
    <item>
      <title>Re: Admins can't see private searches/reports/alerts</title>
      <link>https://community.splunk.com/t5/Security/Admins-can-t-see-private-searches-reports-alerts/m-p/242868#M6768</link>
      <description>&lt;P&gt;I don't think you can actually view the dashboard - you can only see the object in the manager list, and edit its permissions.  You will have to manually set permissions to allow the admins role to "read" the view/search etc. &lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2016 14:03:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Admins-can-t-see-private-searches-reports-alerts/m-p/242868#M6768</guid>
      <dc:creator>jplumsdaine22</dc:creator>
      <dc:date>2016-01-25T14:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: Admins can't see private searches/reports/alerts</title>
      <link>https://community.splunk.com/t5/Security/Admins-can-t-see-private-searches-reports-alerts/m-p/242869#M6769</link>
      <description>&lt;P&gt;Check under &lt;CODE&gt;Settings -&amp;gt; All Configurations&lt;/CODE&gt; . You should be able to see all dashboards under config type view and similarly other objects as well. You might need to edit permissions there to share from private to Global to list them under dashboards&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2016 02:02:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Admins-can-t-see-private-searches-reports-alerts/m-p/242869#M6769</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2016-01-26T02:02:46Z</dc:date>
    </item>
    <item>
      <title>Re: Admins can't see private searches/reports/alerts</title>
      <link>https://community.splunk.com/t5/Security/Admins-can-t-see-private-searches-reports-alerts/m-p/242870#M6770</link>
      <description>&lt;P&gt;Yep -- you're right for this one. Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2016 10:41:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Admins-can-t-see-private-searches-reports-alerts/m-p/242870#M6770</guid>
      <dc:creator>alekksi</dc:creator>
      <dc:date>2016-01-26T10:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: Admins can't see private searches/reports/alerts</title>
      <link>https://community.splunk.com/t5/Security/Admins-can-t-see-private-searches-reports-alerts/m-p/242871#M6771</link>
      <description>&lt;P&gt;Seems to work fine. Thanks a lot mate &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2016 10:41:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Admins-can-t-see-private-searches-reports-alerts/m-p/242871#M6771</guid>
      <dc:creator>alekksi</dc:creator>
      <dc:date>2016-01-26T10:41:29Z</dc:date>
    </item>
    <item>
      <title>Re: Admins can't see private searches/reports/alerts</title>
      <link>https://community.splunk.com/t5/Security/Admins-can-t-see-private-searches-reports-alerts/m-p/242872#M6772</link>
      <description>&lt;P&gt;you are welcome&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2016 10:55:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Admins-can-t-see-private-searches-reports-alerts/m-p/242872#M6772</guid>
      <dc:creator>chimell</dc:creator>
      <dc:date>2016-01-26T10:55:53Z</dc:date>
    </item>
    <item>
      <title>Re: Admins can't see private searches/reports/alerts</title>
      <link>https://community.splunk.com/t5/Security/Admins-can-t-see-private-searches-reports-alerts/m-p/242873#M6773</link>
      <description>&lt;P&gt;Worked like a charm!&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2016 02:39:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Admins-can-t-see-private-searches-reports-alerts/m-p/242873#M6773</guid>
      <dc:creator>norbertkiammacl</dc:creator>
      <dc:date>2016-05-25T02:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: Admins can't see private searches/reports/alerts</title>
      <link>https://community.splunk.com/t5/Security/Admins-can-t-see-private-searches-reports-alerts/m-p/242874#M6774</link>
      <description>&lt;P&gt;I dont follow. Going to Settings -&amp;gt; All Configurations just brings you to 20+ pages of indecipherable object names. The answer for this question does not address what someone using Splunk Web would do in order to change the permissions required to see alerts that a user has made and never shared globally. &lt;/P&gt;</description>
      <pubDate>Tue, 06 Nov 2018 22:34:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Admins-can-t-see-private-searches-reports-alerts/m-p/242874#M6774</guid>
      <dc:creator>hredd</dc:creator>
      <dc:date>2018-11-06T22:34:01Z</dc:date>
    </item>
  </channel>
</rss>

