Reporting

What are the permissions / capabilities required for users to be able to see the "Report Acceleration Summaries" page?

nwales
Path Finder

What are the permissions / criteria required for users to be able to see the 'Report Acceleration Summaries' page?

Right now, even users with the 'Accelerate Searches' role do not get the option in the settings drop-down.

This is running 6.2.1 with search head clustering.

It works for myself as an admin.

0 Karma

mattness
Splunk Employee
Splunk Employee

Can your users see any other Settings page links? If they cannot see other admin-only Settings pages that you have access to, it could be that you need to expand their access in the local.meta file as described here: http://docs.splunk.com/Documentation/Splunk/6.2.2/Security/Addmanagementaccesstocustomroles

Note that in this topic, what is referred to as "Manager" is now called "Settings" in the product.

mattness
Splunk Employee
Splunk Employee

Ah, looks like someone beat me to this response!

0 Karma

kserra_splunk
Splunk Employee
Splunk Employee

Per our docs

Your role must have the schedule_search and accelerate_search capabilities.

http://docs.splunk.com/Documentation/Splunk/6.2.2/Knowledge/Manageacceleratedsearchsummaries

nwales
Path Finder

I created an 'accelerated user' role which has both of these capabilities.

Said users can create accelerated searches however they cannot see the link to the Report Acceleration Summaries page.

0 Karma

acharlieh
Influencer

Not sure, but I wonder if the power role is required for the link...

In ./etc/apps/search/metadata/default.meta I see:

[manager/summarization]
access = read : [ power ], write : [ admin ]

So maybe you could add to local.meta

[manager/summarization]
access = read : [ accelerated user ], write : [ admin ]

? But that is a wild stab in the dark

Get Updates on the Splunk Community!

Platform Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestIntroducing Splunk Edge Processor, simplified data ...

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...