<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to set user permission for &amp;quot;Show Source&amp;quot; in Event Actions drop down? in Security</title>
    <link>https://community.splunk.com/t5/Security/How-to-set-user-permission-for-quot-Show-Source-quot-in-Event/m-p/365454#M9108</link>
    <description>&lt;P&gt;Actually I mean  Event Actions  - &amp;gt; Show Source&lt;/P&gt;</description>
    <pubDate>Wed, 04 Oct 2017 16:36:11 GMT</pubDate>
    <dc:creator>baiyungao</dc:creator>
    <dc:date>2017-10-04T16:36:11Z</dc:date>
    <item>
      <title>How to set user permission for "Show Source" in Event Actions drop down?</title>
      <link>https://community.splunk.com/t5/Security/How-to-set-user-permission-for-quot-Show-Source-quot-in-Event/m-p/365452#M9106</link>
      <description>&lt;P&gt;The splunk administrator in my organization removed some permission for my role, the consequence is that I don't have permission to run "Show Source" action. Please advise, what is the configuration Item to add "View source" feature to a role permission.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2017 20:49:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-set-user-permission-for-quot-Show-Source-quot-in-Event/m-p/365452#M9106</guid>
      <dc:creator>baiyungao</dc:creator>
      <dc:date>2017-10-03T20:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to set user permission for "Show Source" in Event Actions drop down?</title>
      <link>https://community.splunk.com/t5/Security/How-to-set-user-permission-for-quot-Show-Source-quot-in-Event/m-p/365453#M9107</link>
      <description>&lt;P&gt;You may be able to edit the dashboard by adding "/edit" to the end of the URL.&lt;BR /&gt;
For example,&lt;BR /&gt;
  &lt;CODE&gt;&lt;A href="http://localhost:8000/en-GB/app/search/test_dashboard/edit" target="test_blank"&gt;http://localhost:8000/en-GB/app/search/test_dashboard/edit&lt;/A&gt;&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Depending on the rights, you may need to save it under a different dashboard name&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2017 23:27:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-set-user-permission-for-quot-Show-Source-quot-in-Event/m-p/365453#M9107</guid>
      <dc:creator>sduff_splunk</dc:creator>
      <dc:date>2017-10-03T23:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to set user permission for "Show Source" in Event Actions drop down?</title>
      <link>https://community.splunk.com/t5/Security/How-to-set-user-permission-for-quot-Show-Source-quot-in-Event/m-p/365454#M9108</link>
      <description>&lt;P&gt;Actually I mean  Event Actions  - &amp;gt; Show Source&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2017 16:36:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-set-user-permission-for-quot-Show-Source-quot-in-Event/m-p/365454#M9108</guid>
      <dc:creator>baiyungao</dc:creator>
      <dc:date>2017-10-04T16:36:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to set user permission for "Show Source" in Event Actions drop down?</title>
      <link>https://community.splunk.com/t5/Security/How-to-set-user-permission-for-quot-Show-Source-quot-in-Event/m-p/365455#M9109</link>
      <description>&lt;P&gt;You need to check the workflow action under &lt;CODE&gt;Settings&lt;/CODE&gt; &amp;gt; &lt;CODE&gt;Fields&lt;/CODE&gt; &amp;gt; &lt;CODE&gt;Workflow actions&lt;/CODE&gt;. Either the &lt;CODE&gt;show_source&lt;/CODE&gt; action will have been removed, disabled, or the permissions for the action has been altered. &lt;/P&gt;

&lt;P&gt;Normally, these default actions are Global, which is Read for Everyone, Write for admin.&lt;/P&gt;

&lt;P&gt;You need to check (with your Splunk Admin) what this has been changed to, and ensure that a role you belong to has Read access for the &lt;CODE&gt;show_source&lt;/CODE&gt; workflow action.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2017 01:25:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-set-user-permission-for-quot-Show-Source-quot-in-Event/m-p/365455#M9109</guid>
      <dc:creator>sduff_splunk</dc:creator>
      <dc:date>2017-10-05T01:25:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to set user permission for "Show Source" in Event Actions drop down?</title>
      <link>https://community.splunk.com/t5/Security/How-to-set-user-permission-for-quot-Show-Source-quot-in-Event/m-p/365456#M9110</link>
      <description>&lt;P&gt;Apologies, you were quite clear and I was in error. I've posted another solution which should address your query.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2017 01:26:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-set-user-permission-for-quot-Show-Source-quot-in-Event/m-p/365456#M9110</guid>
      <dc:creator>sduff_splunk</dc:creator>
      <dc:date>2017-10-05T01:26:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to set user permission for "Show Source" in Event Actions drop down?</title>
      <link>https://community.splunk.com/t5/Security/How-to-set-user-permission-for-quot-Show-Source-quot-in-Event/m-p/365457#M9111</link>
      <description>&lt;P&gt;Did you solve this issue? (The answers below don't work for me. The workflow action under Settings &amp;gt; Fields &amp;gt; Workflow actions hasn't been changed, the permissions for the action are fine, including read access for the show_source workflow action.)&lt;/P&gt;</description>
      <pubDate>Tue, 11 Dec 2018 13:00:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-set-user-permission-for-quot-Show-Source-quot-in-Event/m-p/365457#M9111</guid>
      <dc:creator>adckia</dc:creator>
      <dc:date>2018-12-11T13:00:01Z</dc:date>
    </item>
  </channel>
</rss>

