Monitoring Splunk

We need to give only DMC access to users from L1 team.

Path Finder

We need to give only DMC access to users from L1 team. We dont need the team to have admin or power role access can some one please help me with the capabiltiy we can use so that a set of users can only view the DMC console and raise alarms incase the Splunk cluster is not complete.

Tags (2)
0 Karma


Hi vikram_m,

you can create a new role with these settings:

cumulativeRTSrchJobsQuota = 0
cumulativeSrchJobsQuota = 0
dispatch_rest_to_indexers = enabled
importRoles = power;user
license_tab = enabled
list_deployment_client = enabled
list_deployment_server = enabled
list_forwarders = enabled
list_health = enabled
list_httpauths = enabled
list_indexer_cluster = enabled
list_indexerdiscovery = enabled
list_search_head_clustering = enabled
list_search_scheduler = enabled
list_settings = enabled
rest_properties_get = enabled
list_health = enabled
rest_apps_view = enabled
list_indexer_cluster = enabled
list_search_head_clustering = enabled
edit_dist_peer = enabled
srchIndexesAllowed = _*
srchIndexesDefault = _*
srchMaxTime = 0

and allow this role read access to the Monitoring Console app. This will do the task.

Hope this helps ...

cheers, MuS

Ultra Champion

Hello there,
the DMC relay heavily on data that resides in _* indexes. i splunk admins have access to these indexes but you can allow any other user to access those as well.
when configuring a role, scroll all the way down and ass "All Internal Indexes" to "Indexes" (last box on that page)
where do you have the DMC configured? if it is according to best practices and DMC has its own dedicated Splunk instance, i think the best way is to create that unique role and also allow only to this group access to that particular Splunk instance.
hope it helps

0 Karma

Ultra Champion

In addition, since the DMC or MC is an admin app you need to go and adjust its permissions -

alt text

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...