Security

Default app for new users in Splunk 7.2

elsadso
Engager

Dear all,

I am facing two challenges with Splunk 7.2.0.

  1. Users who have the "edit_user" capability are unable to set a users default app. Also I cannot find any suitable capability for this task. It seems that really powerful capabilities like "admin_all_objects" are necessary for this simple task. Could you tell me, which is a suitable capability for a user administrator who should create users and assign default apps only?
  2. I cannot find out, how the inheritance of the default app from a role is supposed to work when using Splunk user administration. Upon creating a new user, it is always necessary to select at least one app. Even if the user is created by a user administrator that may not set a default app (see point 1), the app will be Launcher(Home) always. The inheritance seems to never have any effect when using the Splunk user administration as there is no "default" item to select nor can the field be left empty. How is this supposed to work? I cannot find an answer in the docs unfortunately.

Thank you for your help

lmethwani_splun
Splunk Employee
Splunk Employee

Hi @elsadso ,

  1. admin_all_objects is the only capability through which you can achieve this. In splunk, setting a users' default app can be changed using user Preferences. Only admin can change any user's default app and no one else. What is the use case that any user can change other users' default app ?
    https://docs.splunk.com/Documentation/Splunk/7.2.4/Admin/User-prefsconf

  2. Default app from role is inherited because all users must have some app selected as default app. So, splunk will by default have an app inherited from their role, any user can change it from Preferences tab.

For an example, if I create a role and I want all users with xyz app to have default then, I can be control while assigning the role to any user. After that, users' preference is considered highest which will override the inherited app from the role.

Ref Doc: https://docs.splunk.com/Documentation/Splunk/7.3.1/Admin/ConfigureSplunktoopeninanapp

Hope this helps 🙂

0 Karma

riccardofuchs
Engager

I upvoted your question because your '2nd challenge' matches mine. It appears to me that the option to NOT select any default app is missing...
Hopefully some Splunk professional takes time to find a more convenient answer.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...