Reporting

How to configure a role to disable the capability to create saved searches?

jmallorquin
Builder

Hi,

We have configured a role to disable the capability to create saved searches, adding only the capabilities:
-change_own_password
-export_results_is_visible
-rest_properties_get
-search

But I have found that users with this role still can create saved searches.

Any advice?

Regards,

0 Karma

inventsekar
SplunkTrust
SplunkTrust

maybe, try disabling these capabilities for this role..
schedule_search Schedule saved searches, create and update alerts, and review triggered alert information.
schedule_rtsearch Schedule real-time saved searches. In order for a user to use this capability their role must also have the schedule_search capability.

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

jmallorquin
Builder

Hi inventsekar,

Did you see any of the capabilities that you said in the list that I provide of the role that i configure?

Regards,

0 Karma
Get Updates on the Splunk Community!

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

What's New in Splunk Observability - October 2025

What’s New?    We’re excited to announce the latest enhancements to Splunk Observability Cloud and share ...