All Apps and Add-ons

Lookup File Editor App: How can a Splunk user with only a user role make changes to existing CSV files?

VeEn
Explorer

Hi,

We have the problem that we want Splunk users to be able to change existing CSV files, but every time a user with a user role wants to change a field, the editor returns the forbidden-error, even if the user created the file.

So far I tried fidgeting with the rights of the path and the specific file, but without any effect.

Is there some configuration wrong or is there a way to achieve this?

Best regards,
Verena

0 Karma
1 Solution

hortonew
Builder

You should be able to grant access via default or local.meta in the metadata folder. For instance, the following would allow write access to admins and the group mySplunkEditorGroup for all objects as part of an app.

[]
access = read : [ * ], write : [admin,mySplunkEditorGroup]
export = system

View solution in original post

hortonew
Builder

You should be able to grant access via default or local.meta in the metadata folder. For instance, the following would allow write access to admins and the group mySplunkEditorGroup for all objects as part of an app.

[]
access = read : [ * ], write : [admin,mySplunkEditorGroup]
export = system

VeEn
Explorer

It was default.meta and it works. Thanks!

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...