<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Read Only Executive Summary Splunk ES in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Read-Only-Executive-Summary-Splunk-ES/m-p/684866#M11972</link>
    <description>&lt;P&gt;+1 with&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/49853"&gt;@TheLawsOfChaos&lt;/a&gt;, It's a common practise to create a Role with "Read Only" permission. You have any further questions / issues with respect to this&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/259153"&gt;@treven&lt;/a&gt;?&lt;/P&gt;</description>
    <pubDate>Sat, 20 Apr 2024 14:41:24 GMT</pubDate>
    <dc:creator>meetmshah</dc:creator>
    <dc:date>2024-04-20T14:41:24Z</dc:date>
    <item>
      <title>Read Only Executive Summary Splunk ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Read-Only-Executive-Summary-Splunk-ES/m-p/678270#M11923</link>
      <description>&lt;P&gt;Is there a way to give a user read-only access to only a specific dashboard on Splunk ES such as the Executive Summary dashboard? Any assistance would be greatly appreciated!&amp;nbsp;&lt;/P&gt;&lt;P&gt;*Edit&lt;/P&gt;&lt;P&gt;Sorry we have the user role and user created but we are unable to restrict it to a single dashboard, we can specify an app such as ES but have been unsuccessful in getting a default dashboard set. When you land on ES there is the "Security Posture"&amp;nbsp; "Incident Review" "App Configuration" etc settings. Would it be possible to change one of these from "Security Posture" to "Executive Summary" so that way they are just a click away from the appropriate dashboard?&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 14:55:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Read-Only-Executive-Summary-Splunk-ES/m-p/678270#M11923</guid>
      <dc:creator>treven</dc:creator>
      <dc:date>2024-02-22T14:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: Read Only Executive Summary Splunk ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Read-Only-Executive-Summary-Splunk-ES/m-p/683546#M11963</link>
      <description>&lt;P&gt;To lock a single dashboard down, you would want to create a new custom user that does&amp;nbsp;&lt;STRONG&gt;not&lt;/STRONG&gt; inherit the user permission.&lt;/P&gt;&lt;P&gt;Then you would grant that user read permissions to that single dashboard.&amp;nbsp; Then the user can get to it via the link, but not even going to the app to browse for it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If they can view ES, they can view all the dashboards (by default). You could go dashboard by dashboard, and change the custom nav to reflect it. But if you want the user to only see that one part of ES, I'd recommend the method I laid out up top.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 03:01:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Read-Only-Executive-Summary-Splunk-ES/m-p/683546#M11963</guid>
      <dc:creator>TheLawsOfChaos</dc:creator>
      <dc:date>2024-04-08T03:01:36Z</dc:date>
    </item>
    <item>
      <title>Re: Read Only Executive Summary Splunk ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Read-Only-Executive-Summary-Splunk-ES/m-p/684866#M11972</link>
      <description>&lt;P&gt;+1 with&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/49853"&gt;@TheLawsOfChaos&lt;/a&gt;, It's a common practise to create a Role with "Read Only" permission. You have any further questions / issues with respect to this&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/259153"&gt;@treven&lt;/a&gt;?&lt;/P&gt;</description>
      <pubDate>Sat, 20 Apr 2024 14:41:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Read-Only-Executive-Summary-Splunk-ES/m-p/684866#M11972</guid>
      <dc:creator>meetmshah</dc:creator>
      <dc:date>2024-04-20T14:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: Read Only Executive Summary Splunk ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Read-Only-Executive-Summary-Splunk-ES/m-p/686364#M11980</link>
      <description>&lt;P&gt;Sorry for the late response on this but this is exactly what we did created a user and role separate from the others exec_view and assigned that role read-only permissions and assigned it to specific users. Thanks for the information!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2024 17:26:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Read-Only-Executive-Summary-Splunk-ES/m-p/686364#M11980</guid>
      <dc:creator>treven</dc:creator>
      <dc:date>2024-05-03T17:26:29Z</dc:date>
    </item>
  </channel>
</rss>

