I am new to the Splunk App for VMware.
I gave my VMWare admin the "splunk_vmware_admin" user role in Splunk.
He said that and now he can see all installed "Apps" and "Reports" that he didn't use to see.
How can I take away the "admin_all_objects" from the VMware admin and still allow them to control the DCN's?
$app$_admin roles are additive to Splunk's native admin roles -- you're stating "this is a Splunk admin who can also admin VMW", not "this is a Splunk user who admins the VMW app".
My VMware admin is not a splunk admin. I want to delegate the VMWARE admin role to the VMware Admins and not have them admin all of splunk. Is this possible?
One of the Capabilities
showing for the splunk_vmware_admin
is admin_all_objects
This essentially gives the "VMWare Admin" the right to be a "Splunk Admin"