<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom Role on ES in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Custom-Role-on-ES/m-p/751960#M12633</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/28010"&gt;@PrewinThomas&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I went ahead and set the inheritance for ess_user, and now I can see the notables on Mission Control with a user with the custom role. Unfortunately, this doesn't fix the root issue, which I think is more in-line with what&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;mentioned, because even granting additional permission to own notables I still get errors when assigning the notables.&lt;/P&gt;&lt;P&gt;I would rather not inherit ess_analyst because it has permissions that I do not want to grant to this role.&lt;/P&gt;</description>
    <pubDate>Thu, 21 Aug 2025 07:31:38 GMT</pubDate>
    <dc:creator>akai</dc:creator>
    <dc:date>2025-08-21T07:31:38Z</dc:date>
    <item>
      <title>Custom Role on ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Custom-Role-on-ES/m-p/751853#M12626</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have create a custom role and assigned the same permissions as&amp;nbsp;ess_user, including adding it to the&amp;nbsp;enforce_es_permissions setting. But for whatever reason the user doesn't see any notables on Mission Control (I get a&amp;nbsp;&lt;SPAN&gt;&lt;EM&gt;Search did not return any findings or investigations&lt;/EM&gt;). User also has access to the notable index and can see the events there when doing a normal search.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If I assign the ess_user role to the same user, the Mission Control panel gets populated.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Running on Splunk Cloud.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Anything I am missing or tips for debugging permission issues?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 11:59:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Custom-Role-on-ES/m-p/751853#M12626</guid>
      <dc:creator>akai</dc:creator>
      <dc:date>2025-08-19T11:59:49Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Role on ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Custom-Role-on-ES/m-p/751855#M12627</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/311626"&gt;@akai&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As well as the new role having the capabilities from ess_user, you will also need to ensure it has permissions to see the relevant lookups , indexes and other knowledge objects which are managed within the app contexts not within the role itself.&lt;/P&gt;&lt;P&gt;Have you added your new custom role to the read permissions of the ES lookups and other knowledge objects such as the lookup definitions and macros?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 12:05:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Custom-Role-on-ES/m-p/751855#M12627</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-08-19T12:05:00Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Role on ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Custom-Role-on-ES/m-p/751858#M12628</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the quick response!&lt;/P&gt;&lt;P&gt;As far as I can see the permissions on lookups and knowledge objects owned by ES are shared globally with Read all, so I assume at least being able to get the notables populated in Mission Control should be happening, as I mentioned, searching in the notable index does return data (the role also has access to index=*).&lt;/P&gt;&lt;P&gt;Anything specific I could check here? I am not sure if anything shows up in the internal indexes, regarding errors or whatnot.&lt;/P&gt;&lt;P&gt;EDIT: I would also add that I attempt to clone ess_user, but that did not change the result.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 12:42:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Custom-Role-on-ES/m-p/751858#M12628</guid>
      <dc:creator>akai</dc:creator>
      <dc:date>2025-08-19T12:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Role on ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Custom-Role-on-ES/m-p/751881#M12629</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/311626"&gt;@akai&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Instead of cloning, try role &lt;STRONG&gt;inheritance,&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;ess_user&lt;/STRONG&gt; permissions may not be sufficient for Mission Control. Also make sure relevant &lt;STRONG&gt;mc_*&lt;/STRONG&gt; capabilities are available for the new role.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Refer&lt;/STRONG&gt; below, for creating role in Mission Control.&lt;BR /&gt;#&lt;A href="https://help.splunk.com/en/splunk-enterprise-security-7/mission-control/investigate-and-respond-to-threats/manage-splunk-mission-control/manage-roles-and-capabilities-for-splunk-mission-control-users" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise-security-7/mission-control/investigate-and-respond-to-threats/manage-splunk-mission-control/manage-roles-and-capabilities-for-splunk-mission-control-users&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; There might be some delay before your changes reflect in Mission Control.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 04:08:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Custom-Role-on-ES/m-p/751881#M12629</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-08-20T04:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Role on ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Custom-Role-on-ES/m-p/751960#M12633</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/28010"&gt;@PrewinThomas&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I went ahead and set the inheritance for ess_user, and now I can see the notables on Mission Control with a user with the custom role. Unfortunately, this doesn't fix the root issue, which I think is more in-line with what&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;mentioned, because even granting additional permission to own notables I still get errors when assigning the notables.&lt;/P&gt;&lt;P&gt;I would rather not inherit ess_analyst because it has permissions that I do not want to grant to this role.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 07:31:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Custom-Role-on-ES/m-p/751960#M12633</guid>
      <dc:creator>akai</dc:creator>
      <dc:date>2025-08-21T07:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Role on ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Custom-Role-on-ES/m-p/752037#M12635</link>
      <description>&lt;P&gt;After changing some more permissions and also changing the status transitions permissions (which took me forever to figure out I needed to do), everything seems to be working when inheriting the &lt;STRONG&gt;ess_user&lt;/STRONG&gt; role, which is fine by me. I'm still not sure why this is necessary, but I can live with it for now.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2025 09:08:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Custom-Role-on-ES/m-p/752037#M12635</guid>
      <dc:creator>akai</dc:creator>
      <dc:date>2025-08-22T09:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Role on ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Custom-Role-on-ES/m-p/760078#M12888</link>
      <description>&lt;P&gt;I'm having the same issue as OP, what are the specific conf files that control whether a role get permissions to everything in enterprise security? Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 19:41:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Custom-Role-on-ES/m-p/760078#M12888</guid>
      <dc:creator>dspencer</dc:creator>
      <dc:date>2026-04-09T19:41:39Z</dc:date>
    </item>
  </channel>
</rss>

