Getting Data In

Minimal capabilities required for adding events via Splunk REST API

yitzarad
Path Finder

Hi,

I'm trying to add events into an existing index, via the REST API (specifically, using javascript-sdk).

Everything works fine when using a powerful user/role.

Now, I'm trying to limit the capabilities of that user, but cannot find any relevant capability for adding data into index, via the REST API.

What are the "least privileges" in this case?

Tags (3)
0 Karma
1 Solution

LukeMurphey
Champion

You'll need "edit_tcp" to be able create events via the "/services/receivers/simple" API.

View solution in original post

LukeMurphey
Champion

You'll need "edit_tcp" to be able create events via the "/services/receivers/simple" API.

LukeMurphey
Champion

Yeah, no doubt! I only found out what the necessary permission was after spending way to much on it.

0 Karma

yitzarad
Path Finder

It's working, thank you!
BTW, "edit_tcp" is not so indicative description... 😕

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...