Security

How to allow global permission for a user without enabling access to the Monitoring Console?

ash2l
Path Finder

Splunkers,

We have a unique situation while coming up with a role for power user: we don't want them (power users) to click on Distributed Management Console (DMC or now, it's called Monitoring Console) which is recommended by Splunk to turned off due to high CPU consumption on search heads. The Power users need to have access to provide global permission to share field extractions, lookups, tags etc. I could not find a good way (a specific capability) that keep the global permission to the power user role but deactivate the Monitoring Console access.

Any help to resolve this would be appreciated.

Amit

0 Karma
1 Solution

kmccririe_splun
Splunk Employee
Splunk Employee

If you click on the app drop down and click managed apps. You will see a list of all the apps you have installed. You will see the Monitoring Console as an app, you can edit the permissions of the app so that the power user role doesn't have read or write permissions.

View solution in original post

kmccririe_splun
Splunk Employee
Splunk Employee

If you click on the app drop down and click managed apps. You will see a list of all the apps you have installed. You will see the Monitoring Console as an app, you can edit the permissions of the app so that the power user role doesn't have read or write permissions.

woodcock
Esteemed Legend

Or disable it entirely.

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...