Archive

Permission issue in Alerts created in Search & Reporting App

Path Finder

In Splunk Cloud a user (A) has created multiple alerts (around 50+ alerts) in the Search & Reporting App and he has been assigned as an admin role. Similarly a same guy from his team (B) has been assigned to the same role (admin) but he cant able to edit the search which has been created by (A) and the only option it is available for him is "Clone" or "Embed".

So in a single shot can we able to change the permissions for all the alerts which has been created by (A) user so that (B) can able to edit or write the search query.

I navigated to Manage Apps and checked into "Search & Reporting App" and then i have provided the write permission for the admins and saved it and also reloaded the authentication but still (B) user cant able to edit the query which has been created by (A).

So is there any way to change the write permissions in one shot for the alerts which has been created in the "Search & Reporting App" by (A) so that (B) can able to modify the query and save it.

Tags (1)
0 Karma

Path Finder

Kindly help on this request.

0 Karma

Path Finder

Can anyone help on the request

0 Karma