Security

Disable Report Acceleration for Specifc Roles - however do not disable report scheduling?

t9445
Path Finder

[Were running v6.0.1]

Hi, quick question please, from the documentation if we want to disable a user-role from being able to enabe report-acceleration on saved-searches -- we have to disable the schedule_search capability as well.

e.g. from the docs -- schedule_search: Schedule saved searches, create and update alerts, review triggered alert information, and turn on report acceleration for searches.

However, is there a way to allow a user-role to schedule saved searches, etc. - however NOT be able to enable report-acceleration on their searches?

Appreciate any tips

thanks

Tags (2)
0 Karma
1 Solution

drrushi_splunk
Splunk Employee
Splunk Employee

A new capability was introduced in version 6.1 which specifically enables/disables the accelerate feature.
In authorize.conf or via the UI role management page you could set the 'accelerate_search' capability.
In previous versions there is not an easy way to disable this option.

View solution in original post

drrushi_splunk
Splunk Employee
Splunk Employee

A new capability was introduced in version 6.1 which specifically enables/disables the accelerate feature.
In authorize.conf or via the UI role management page you could set the 'accelerate_search' capability.
In previous versions there is not an easy way to disable this option.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...