Alerting

Role Capabilities for splunkd-log

eekanem
New Member

Hi, what is the minimum capability without admin_for_all for a non-admin user to access splunkd-log object?

Labels (1)
0 Karma

rupkumar4sec
Path Finder

I am not sure what you mean by splunkd-log object but if you are trying to access splunkd internal logs, you just need to add  those internal indexes or "_*"  to srchIndexesAllowed . 

0 Karma

eekanem
New Member

That does not seem to be enough for me. I noticed that with the power user I could access the splunk internal logs so I added the capabilities to my role but it still does not work.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

New This Month - Observability Updates Give Extended Visibility and Improve User ...

This month is a collection of special news! From Magic Quadrant updates to AppDynamics integrations to ...

Intro to Splunk Synthetic Monitoring

In our last post, we mentioned that the 3 key pieces of observability – metrics, logs, and traces – provide ...