<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cloned Role in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Cloned-Role/m-p/760079#M12889</link>
    <description>&lt;P&gt;Thanks for the response.&lt;/P&gt;&lt;P&gt;I've tried to add my role to the 'data inputs -&amp;gt; 'app manager' -&amp;gt; 'enforce_es_permissions", but that just gives me an error.&lt;/P&gt;&lt;P&gt;Do you have or know of specific documentation of how to set role permissions of a search head cluster?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 09 Apr 2026 19:51:28 GMT</pubDate>
    <dc:creator>dspencer</dc:creator>
    <dc:date>2026-04-09T19:51:28Z</dc:date>
    <item>
      <title>Cloned Role</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Cloned-Role/m-p/760067#M12886</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I created a new role that is the same as ess_analyst but it doesn't have any inheritance, all the capabilities are native. My new role can't see investigations and my research hasn't given me any answers.&lt;/P&gt;&lt;P&gt;All the permissions I can think of are wide open, is there anything I'm missing or is it required to inherit from a default role?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 13:38:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Cloned-Role/m-p/760067#M12886</guid>
      <dc:creator>dspencer</dc:creator>
      <dc:date>2026-04-09T13:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cloned Role</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Cloned-Role/m-p/760077#M12887</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/262462"&gt;@dspencer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you added the new role with permissions to the relevant ES apps and lookups etc? The capabilities themselves aren’t enough, they need permission to the knowledge objects too.&amp;nbsp;&lt;BR /&gt;you might find that inheriting the original role with your custom role would work better?&lt;/P&gt;&lt;P&gt;see this other post for more info&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Splunk-Enterprise-Security/Custom-Role-on-ES/m-p/751853#M12626" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Enterprise-Security/Custom-Role-on-ES/m-p/751853#M12626&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt; &lt;STRONG&gt;Did this answer help you? If so, please consider&lt;/STRONG&gt;:&lt;/P&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 18:39:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Cloned-Role/m-p/760077#M12887</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2026-04-09T18:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cloned Role</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Cloned-Role/m-p/760079#M12889</link>
      <description>&lt;P&gt;Thanks for the response.&lt;/P&gt;&lt;P&gt;I've tried to add my role to the 'data inputs -&amp;gt; 'app manager' -&amp;gt; 'enforce_es_permissions", but that just gives me an error.&lt;/P&gt;&lt;P&gt;Do you have or know of specific documentation of how to set role permissions of a search head cluster?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 19:51:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Cloned-Role/m-p/760079#M12889</guid>
      <dc:creator>dspencer</dc:creator>
      <dc:date>2026-04-09T19:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cloned Role</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Cloned-Role/m-p/760080#M12890</link>
      <description>&lt;P&gt;For a search head cluster, it replicates changes that you make via the GUI, CLI or REST calls. So, for example if you created the role in the GUI that would have been pushed out to the rest of the cluster and then as per the documentation you updated the ACLs via the "enforce_es_permissions" the ES portion is sorted but this is just the capabilities of what a user can do and not the permissions of what they can access...&lt;/P&gt;&lt;P&gt;Now you will either need to edit each App/Add-on/Knowledge Object manually in the GUI to allow the permissions, or you can create a local.meta in each App/Add-on on the Deployer and do it for the entire App/Add-on or specific types of knowledge objects within or specific knowledge objects themselves (not recommended from a deployer).&lt;/P&gt;&lt;P&gt;Ref:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://help.splunk.com/en/splunk-enterprise-security-8/install/8.5/installation/capability-reference-for-splunk-enterprise-security" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise-security-8/install/8.5/installation/capability-reference-for-splunk-enterprise-security&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A style="font-family: inherit; background-color: #ffffff;" href="https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/10.2/update-search-head-cluster-members/configuration-updates-that-the-cluster-replicates" target="_blank"&gt;Configuration updates that the cluster replicates | Splunk Enterprise (last updated 2026-01-08T16:29:13.158Z)&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://help.splunk.com/en/splunk-enterprise/manage-knowledge-objects/knowledge-management-manual/10.2/get-started-with-knowledge-objects/manage-knowledge-object-permissions" target="_blank"&gt;Manage knowledge object permissions | Splunk Enterprise, Splunk Cloud Platform (last updated 2026-01-09T01:53:52.904Z)&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 23:22:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Cloned-Role/m-p/760080#M12890</guid>
      <dc:creator>lmaclean</dc:creator>
      <dc:date>2026-04-09T23:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cloned Role</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Cloned-Role/m-p/760096#M12892</link>
      <description>&lt;P&gt;Thanks everyone for the advise, I've decided to inherit ess_analyst to make life easier.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2026 18:01:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Cloned-Role/m-p/760096#M12892</guid>
      <dc:creator>dspencer</dc:creator>
      <dc:date>2026-04-10T18:01:13Z</dc:date>
    </item>
  </channel>
</rss>

