Hello everyone!
I create the role for splunk users, which will be able to edit alerts.
What capabilities should I choose for such users? To be minimal and sufficient
I believe that's covered by the schedule_search capability.