Reporting

Issue on savedsearches access using custom role on a custom app

tomasofacci
Explorer

Hi, we have a Splunk Server Instance and we have developed several custom app. To limit access we are creating custom roles to limit access only to the related custom app. All is working fine apart the saved search results visualization. Every time that the custom role user try to see a saved search the result is a "Web page not found".
I've already modified permission to grant the custom role on read and write, I've changed the savedsearches.conf of the custom app to work on dispatch as user and dispatch app the custom app.
I've also tried to change the capabilities for the custom role but seems that the only one that fix the issue is the admin_all_objects. But assigning this capability to custom user he will see all other apps so not fine.

Any suggestion?

Thanks and regards
Tomaso

0 Karma

nikita_p
Contributor

Hi,
You can check the accepted answers in the link below. It might help you
https://answers.splunk.com/answers/374936/why-am-i-unable-to-viewdelete-a-users-dashboardsre.html

0 Karma

tomasofacci
Explorer

Hi, today I found out that giving the Read permission to the custom role on Search & Reporting app the custom role can access the saved search available under the custom app. The remaining issue is that I'd not permit that the custom role can see the Search & Reporting app. I tried also to change the parameter ui_dispatch_view from search to custom app in savedsearches.conf but not working. Any suggestion?

Thanks and regards

0 Karma

tomasofacci
Explorer

Contingency 's solution is to give "Read" grant on Search & Reporting to the Custom Role and then remove only the grant to the "search" view of Search & Reporting. It's not the best way because custom role's users will still see the entry for Search & Reporting in app's list and will have a "Page not found" whenever they'll try to select that entry. Let me know if anybody have a better way to manage this situation.

Thanks

0 Karma
Get Updates on the Splunk Community!

Sending Metrics to Splunk Enterprise With the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...

Want a chance to win $500 to the Splunk shop? Take our IT Incident Management Survey!

  Top Trends & Best Practices in Incident ManagementSplunk is partnering up with Constellation Research to ...