Getting Data In

What capabilities do I need to upload files with add data from custom role?

3DGjos
Communicator

Hello, we have to create a role from the scratch. that role has to have the capabilities required to upload .csv files to the environment.

I tried with my admin user and it works just fine, but the custom role is not working. I added the following capabilities to it and still is not working:

edit_monitor
indexes_edit
edit_tcp
search

But still I can't upload files, I've got the error im attaching. if anyone knows what extra capabilities do i need please help me.

Thanks!




 

 





inventsekar
SplunkTrust
SplunkTrust

Hi @3DGjos ..
please try this capability: "edit_tcp"

https://community.splunk.com/t5/Security/When-uploading-a-data-file-why-is-the-progress-bar-getting-...

 

list of all capabilities:

https://docs.splunk.com/Documentation/Splunk/8.0.6/Security/Rolesandcapabilities

check this post as well:

https://community.splunk.com/t5/Getting-Data-In/Capability-to-upload-data-files-via-the-gui-for-a-us...

 

(PS - i have given around 500+ karma points so far, received badge for that, if an answer helped you, a karma point would be nice!. we all should start "Learn, Give Back, Have Fun")

 

 

0 Karma

3DGjos
Communicator

hello, yes I already tried with that capability. but It still gives me the error in putting on my screenshot

0 Karma

Roy_9
Motivator

@3DGjos try assigning both edit_monitor and edit_tcp, it will work.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...