Alerting

Role Capabilities for splunkd-log

eekanem
New Member

Hi, what is the minimum capability without admin_for_all for a non-admin user to access splunkd-log object?

0 Karma

rupkumar4sec
Path Finder

I am not sure what you mean by splunkd-log object but if you are trying to access splunkd internal logs, you just need to add  those internal indexes or "_*"  to srchIndexesAllowed . 

0 Karma

eekanem
New Member

That does not seem to be enough for me. I noticed that with the power user I could access the splunk internal logs so I added the capabilities to my role but it still does not work.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and stall ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...