<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: delete_by_keyword not working in Security</title>
    <link>https://community.splunk.com/t5/Security/delete-by-keyword-not-working/m-p/377095#M9303</link>
    <description>&lt;P&gt;@athorat,&lt;BR /&gt;
Have you posted your entire role definition above or is it only some part of it?&lt;BR /&gt;
Because, search capability is missing in the above role definition which is required and also the &lt;CODE&gt;srchIndexesAllowed&lt;/CODE&gt; has only _audit. Probably you need to add prod-test* as well so that the users can search on those indexes as well.&lt;/P&gt;</description>
    <pubDate>Wed, 03 Apr 2019 13:52:21 GMT</pubDate>
    <dc:creator>renjith_nair</dc:creator>
    <dc:date>2019-04-03T13:52:21Z</dc:date>
    <item>
      <title>delete_by_keyword not working</title>
      <link>https://community.splunk.com/t5/Security/delete-by-keyword-not-working/m-p/377092#M9300</link>
      <description>&lt;P&gt;Want to grant delete permissions for a non admin account for specific prod-test-* indexes&lt;BR /&gt;
 Created a new role and mapped it to an AD group but does not seem to like it. Users still get , Error in 'delete' command: You have insufficient privileges to delete events. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[role_test_access]
srchIndexesAllowed = _audit
deleteIndexesAllowed = prod-test*
delete_by_keyword= enabled
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any suggestions highly appreciated.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Mar 2019 19:15:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/delete-by-keyword-not-working/m-p/377092#M9300</guid>
      <dc:creator>athorat</dc:creator>
      <dc:date>2019-03-30T19:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: delete_by_keyword not working</title>
      <link>https://community.splunk.com/t5/Security/delete-by-keyword-not-working/m-p/377093#M9301</link>
      <description>&lt;P&gt;@athorat,&lt;/P&gt;

&lt;P&gt;Add the below also to your authorize.conf &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;importRoles = can_delete
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sun, 31 Mar 2019 03:10:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/delete-by-keyword-not-working/m-p/377093#M9301</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2019-03-31T03:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: delete_by_keyword not working</title>
      <link>https://community.splunk.com/t5/Security/delete-by-keyword-not-working/m-p/377094#M9302</link>
      <description>&lt;P&gt;Thanks @renjith.nair , Doesnt seem to work. &lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2019 17:54:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/delete-by-keyword-not-working/m-p/377094#M9302</guid>
      <dc:creator>athorat</dc:creator>
      <dc:date>2019-04-01T17:54:31Z</dc:date>
    </item>
    <item>
      <title>Re: delete_by_keyword not working</title>
      <link>https://community.splunk.com/t5/Security/delete-by-keyword-not-working/m-p/377095#M9303</link>
      <description>&lt;P&gt;@athorat,&lt;BR /&gt;
Have you posted your entire role definition above or is it only some part of it?&lt;BR /&gt;
Because, search capability is missing in the above role definition which is required and also the &lt;CODE&gt;srchIndexesAllowed&lt;/CODE&gt; has only _audit. Probably you need to add prod-test* as well so that the users can search on those indexes as well.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 13:52:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/delete-by-keyword-not-working/m-p/377095#M9303</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2019-04-03T13:52:21Z</dc:date>
    </item>
  </channel>
</rss>

