Getting Data In

What capabilities do I need to upload files with add data from custom role?

3DGjos
Communicator

Hello, we have to create a role from the scratch. that role has to have the capabilities required to upload .csv files to the environment.

I tried with my admin user and it works just fine, but the custom role is not working. I added the following capabilities to it and still is not working:

edit_monitor
indexes_edit
edit_tcp
search

But still I can't upload files, I've got the error im attaching. if anyone knows what extra capabilities do i need please help me.

Thanks!




 

 





inventsekar
SplunkTrust
SplunkTrust

Hi @3DGjos ..
please try this capability: "edit_tcp"

https://community.splunk.com/t5/Security/When-uploading-a-data-file-why-is-the-progress-bar-getting-...

 

list of all capabilities:

https://docs.splunk.com/Documentation/Splunk/8.0.6/Security/Rolesandcapabilities

check this post as well:

https://community.splunk.com/t5/Getting-Data-In/Capability-to-upload-data-files-via-the-gui-for-a-us...

 

(PS - i have given around 500+ karma points so far, received badge for that, if an answer helped you, a karma point would be nice!. we all should start "Learn, Give Back, Have Fun")

 

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

3DGjos
Communicator

hello, yes I already tried with that capability. but It still gives me the error in putting on my screenshot

0 Karma

Roy_9
Motivator

@3DGjos try assigning both edit_monitor and edit_tcp, it will work.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...