Security

Field Extraction Restriction

rashi83
Path Finder

Hi,
I want to restrict field extraction capability to users in Splunk system. I want to provide this capability just to Admin users.
If this is not possible , can users create private extractions and only admin can make them global - just trying to put control around the splunk system,

thoughts?

0 Karma

solarboyz1
Builder

can users create private extractions and only admin can make them global

This is exactly how it works. As long as the users do not have write access to the apps, they will only be able to create private objects.

0 Karma

rashi83
Path Finder

@solarboyz1 -What is the name of capability that can control write access to the apps? Could you please share

0 Karma

solarboyz1
Builder

Its not a capability, it's permissions on the app.

App dropdown -> Manage Apps -> {Selected App} Permissions

It lists the roles, and if the have read and/or write permissions.

0 Karma

rashi83
Path Finder

thanks , so I have READ permission to Everyone and Write permission to Admin and Power user only.
But Still I see "normal user" can create global field extractions.

0 Karma

solarboyz1
Builder

https://docs.splunk.com/Documentation/Splunk/7.3.1/Admin/Apparchitectureandobjectownership

To make an object global the user requires the capability:

admin_all_objects capability

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...