Security

How to set user permission for "Show Source" in Event Actions drop down?

baiyungao
New Member

The splunk administrator in my organization removed some permission for my role, the consequence is that I don't have permission to run "Show Source" action. Please advise, what is the configuration Item to add "View source" feature to a role permission.

0 Karma

adckia
New Member

Did you solve this issue? (The answers below don't work for me. The workflow action under Settings > Fields > Workflow actions hasn't been changed, the permissions for the action are fine, including read access for the show_source workflow action.)

0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

You need to check the workflow action under Settings > Fields > Workflow actions. Either the show_source action will have been removed, disabled, or the permissions for the action has been altered.

Normally, these default actions are Global, which is Read for Everyone, Write for admin.

You need to check (with your Splunk Admin) what this has been changed to, and ensure that a role you belong to has Read access for the show_source workflow action.

sduff_splunk
Splunk Employee
Splunk Employee

You may be able to edit the dashboard by adding "/edit" to the end of the URL.
For example,
http://localhost:8000/en-GB/app/search/test_dashboard/edit

Depending on the rights, you may need to save it under a different dashboard name

0 Karma

baiyungao
New Member

Actually I mean Event Actions - > Show Source

0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

Apologies, you were quite clear and I was in error. I've posted another solution which should address your query.

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...