Best method for providing access to Splunk Reports (no search/indexes) to a Splunk role.

Path Finder


I have a set of very non-technical users that has no access to any Splunk indexes, but need access to a hand full of scheduled reports.

Currently I have the role setup with the default search app. The user needs to select Reports->All and then search for the reports by name.

Typing this out, maybe a custom app for this role, so instead of "Reports->All", it would be "Reports->This App's" and they would see a list of their reports?

Any thoughts on the custom app solution or maybe a better alternative? Thanks

0 Karma


As you might already aware, if the user does not have access to index, then the scheduled report should 'run as' owner. Otherwise users will not be able to see the result.

Refer here for more info :

The permissions can be set per knowledge object. So the users will see only those reports where they have "read" access.

Happy Splunking!
0 Karma

Path Finder

Thank you for the reply. Yes, I'm aware that I will need to run the report as owner. Good to know for anyone reading this in the future.

Still looking for some ideas/thoughts about navigation and a better end user experience. Thank you

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2023 Splunk Career Impact Report

We’ve been shouting it from the rooftops! The findings from the 2023 Splunk Career Impact Report showing that ...

Splunk Lantern | Getting Started with Edge Processor, Machine Learning Toolkit ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...