<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Do new roles become grantable roles by default in Splunk? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Do-new-roles-become-grantable-roles-by-default-in-Splunk/m-p/223892#M8267</link>
    <description>&lt;P&gt;Hi gk6565, &lt;/P&gt;

&lt;P&gt;It really depends on from which roles(s) your new role inherits from. &lt;BR /&gt;
Among the system built-in roles, only admin has the edit_roles_grantable Capability by default. &lt;BR /&gt;
If you want to separate and delegate administration tasks between sys-admins and data admins without granting full admin role, restrict grantable capabilities only to the level sub-admins. After you add the edit_roles_grantable capability to the sub-admin role, the role can only create roles with subset of the capabilities that the current user role has. &lt;BR /&gt;
For example: &lt;BR /&gt;
Add new role user_admin by inheriting from power and user, and assigning the following capabilities to the role: &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;edit_roles_grantable&lt;/LI&gt;
&lt;LI&gt;edit_user&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Users in this roles can only assign limited roles to users. &lt;/P&gt;

&lt;P&gt;Hope it helps. Thanks!&lt;BR /&gt;
Hunter&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 12:24:42 GMT</pubDate>
    <dc:creator>hunters_splunk</dc:creator>
    <dc:date>2020-09-29T12:24:42Z</dc:date>
    <item>
      <title>Do new roles become grantable roles by default in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Do-new-roles-become-grantable-roles-by-default-in-Splunk/m-p/223891#M8266</link>
      <description>&lt;P&gt;Do new roles become grantable roles by default in Splunk?&lt;/P&gt;

&lt;P&gt;I'm using Splunk 6.4.2.&lt;/P&gt;

&lt;P&gt;I have created a &lt;CODE&gt;delegated admin&lt;/CODE&gt; role with one user (say &lt;CODE&gt;d_admin&lt;/CODE&gt; for instance). Here is its definition, as given by the &lt;A href="http://mindmajix.com/splunk-training"&gt;splunk&lt;/A&gt; cli:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;role:       delegated_admin
capabilities:           edit_roles_grantable edit_user rest_apps_view rest_properties_get 
default app:        
grantable_roles:            dashboard_designer;dashboard_viewer 
imported_capabilities:          
imported_roles:         
searchable_indexes:         
default_index:  
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;CODE&gt;dashboard_designer&lt;/CODE&gt; and &lt;CODE&gt;dashboard_viewer&lt;/CODE&gt; are nothing special, I just use them to define permissions on apps and dashboards.&lt;/P&gt;

&lt;P&gt;Now, when I log into &lt;CODE&gt;d_admin&lt;/CODE&gt; and create a new role (e.g &lt;CODE&gt;new_role&lt;/CODE&gt;), I can see and manage it just as if it was in the &lt;CODE&gt;grantable_roles&lt;/CODE&gt; list, but it is not. I am not at liberty to test if that survives a cold reboot.&lt;/P&gt;

&lt;P&gt;My question here is : &lt;/P&gt;

&lt;P&gt;Is that a undocumented feature that I can rely on or is that some sort of bug that will bite me if I trust it?&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Kiran&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2017 11:28:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Do-new-roles-become-grantable-roles-by-default-in-Splunk/m-p/223891#M8266</guid>
      <dc:creator>gk6565</dc:creator>
      <dc:date>2017-01-09T11:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: Do new roles become grantable roles by default in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Do-new-roles-become-grantable-roles-by-default-in-Splunk/m-p/223892#M8267</link>
      <description>&lt;P&gt;Hi gk6565, &lt;/P&gt;

&lt;P&gt;It really depends on from which roles(s) your new role inherits from. &lt;BR /&gt;
Among the system built-in roles, only admin has the edit_roles_grantable Capability by default. &lt;BR /&gt;
If you want to separate and delegate administration tasks between sys-admins and data admins without granting full admin role, restrict grantable capabilities only to the level sub-admins. After you add the edit_roles_grantable capability to the sub-admin role, the role can only create roles with subset of the capabilities that the current user role has. &lt;BR /&gt;
For example: &lt;BR /&gt;
Add new role user_admin by inheriting from power and user, and assigning the following capabilities to the role: &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;edit_roles_grantable&lt;/LI&gt;
&lt;LI&gt;edit_user&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Users in this roles can only assign limited roles to users. &lt;/P&gt;

&lt;P&gt;Hope it helps. Thanks!&lt;BR /&gt;
Hunter&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:24:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Do-new-roles-become-grantable-roles-by-default-in-Splunk/m-p/223892#M8267</guid>
      <dc:creator>hunters_splunk</dc:creator>
      <dc:date>2020-09-29T12:24:42Z</dc:date>
    </item>
  </channel>
</rss>

