Security

Default app for new users in Splunk 7.2

elsadso
Engager

Dear all,

I am facing two challenges with Splunk 7.2.0.

  1. Users who have the "edit_user" capability are unable to set a users default app. Also I cannot find any suitable capability for this task. It seems that really powerful capabilities like "admin_all_objects" are necessary for this simple task. Could you tell me, which is a suitable capability for a user administrator who should create users and assign default apps only?
  2. I cannot find out, how the inheritance of the default app from a role is supposed to work when using Splunk user administration. Upon creating a new user, it is always necessary to select at least one app. Even if the user is created by a user administrator that may not set a default app (see point 1), the app will be Launcher(Home) always. The inheritance seems to never have any effect when using the Splunk user administration as there is no "default" item to select nor can the field be left empty. How is this supposed to work? I cannot find an answer in the docs unfortunately.

Thank you for your help

lmethwani_splun
Splunk Employee
Splunk Employee

Hi @elsadso ,

  1. admin_all_objects is the only capability through which you can achieve this. In splunk, setting a users' default app can be changed using user Preferences. Only admin can change any user's default app and no one else. What is the use case that any user can change other users' default app ?
    https://docs.splunk.com/Documentation/Splunk/7.2.4/Admin/User-prefsconf

  2. Default app from role is inherited because all users must have some app selected as default app. So, splunk will by default have an app inherited from their role, any user can change it from Preferences tab.

For an example, if I create a role and I want all users with xyz app to have default then, I can be control while assigning the role to any user. After that, users' preference is considered highest which will override the inherited app from the role.

Ref Doc: https://docs.splunk.com/Documentation/Splunk/7.3.1/Admin/ConfigureSplunktoopeninanapp

Hope this helps 🙂

0 Karma

riccardofuchs
Engager

I upvoted your question because your '2nd challenge' matches mine. It appears to me that the option to NOT select any default app is missing...
Hopefully some Splunk professional takes time to find a more convenient answer.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...