Getting Data In

Minimal capabilities required for adding events via Splunk REST API

yitzarad
Path Finder

Hi,

I'm trying to add events into an existing index, via the REST API (specifically, using javascript-sdk).

Everything works fine when using a powerful user/role.

Now, I'm trying to limit the capabilities of that user, but cannot find any relevant capability for adding data into index, via the REST API.

What are the "least privileges" in this case?

Tags (3)
0 Karma
1 Solution

LukeMurphey
Champion

You'll need "edit_tcp" to be able create events via the "/services/receivers/simple" API.

View solution in original post

LukeMurphey
Champion

You'll need "edit_tcp" to be able create events via the "/services/receivers/simple" API.

LukeMurphey
Champion

Yeah, no doubt! I only found out what the necessary permission was after spending way to much on it.

0 Karma

yitzarad
Path Finder

It's working, thank you!
BTW, "edit_tcp" is not so indicative description... 😕

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...