Dashboards & Visualizations

Permissions required for alert creation and dashboard sharing?

anitiansherlock
Explorer

Hello!

We are working in an environment with extremely locked down permissions that are not under any of the standard user/admin accounts. The requirement for the environment is that all capabilities need to be completely granular and manually added.

We're looking for only the specific capabilities required to be added to our accounts that will allow us to:

  1. Share dashboards with read/write allowances to other users.
  2. Create alerts (specifically ones which will trigger on conditions and email out)

Any help is very appreciated! Thank you!

1 Solution

iandrews_splunk
Splunk Employee
Splunk Employee

creating alerts:

[capability::schedule_search]
* Lets a user schedule saved searches, create and update alerts, and review triggered alert information.

https://docs.splunk.com/Documentation/Splunk/7.0.0/Admin/Authorizeconf

sharing dashboards:

"Users with read access can only save objects for themselves, and require write access to be able to share objects with other users."

seen on "manage apps > select an app > select permissions"

View solution in original post

iandrews_splunk
Splunk Employee
Splunk Employee

creating alerts:

[capability::schedule_search]
* Lets a user schedule saved searches, create and update alerts, and review triggered alert information.

https://docs.splunk.com/Documentation/Splunk/7.0.0/Admin/Authorizeconf

sharing dashboards:

"Users with read access can only save objects for themselves, and require write access to be able to share objects with other users."

seen on "manage apps > select an app > select permissions"

anitiansherlock
Explorer

Great! Thank you for your help on this!

It sounds like the dashboard sharing permissions could be pretty far ranging in this case correct? We would need write permissions to the entire search app to do so?

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...