Security

Disable Report Acceleration for Specifc Roles - however do not disable report scheduling?

t9445
Path Finder

[Were running v6.0.1]

Hi, quick question please, from the documentation if we want to disable a user-role from being able to enabe report-acceleration on saved-searches -- we have to disable the schedule_search capability as well.

e.g. from the docs -- schedule_search: Schedule saved searches, create and update alerts, review triggered alert information, and turn on report acceleration for searches.

However, is there a way to allow a user-role to schedule saved searches, etc. - however NOT be able to enable report-acceleration on their searches?

Appreciate any tips

thanks

Tags (2)
0 Karma
1 Solution

drrushi_splunk
Splunk Employee
Splunk Employee

A new capability was introduced in version 6.1 which specifically enables/disables the accelerate feature.
In authorize.conf or via the UI role management page you could set the 'accelerate_search' capability.
In previous versions there is not an easy way to disable this option.

View solution in original post

drrushi_splunk
Splunk Employee
Splunk Employee

A new capability was introduced in version 6.1 which specifically enables/disables the accelerate feature.
In authorize.conf or via the UI role management page you could set the 'accelerate_search' capability.
In previous versions there is not an easy way to disable this option.

Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

Industry Solutions for Supply Chain and OT, Amazon Use Cases, Plus More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...