How to share Objects between Roles in a App

Path Finder


I am trying to allow different roles to share access to objects (alerts, reports, etc) with one another in the same app. I don't want to give the users admin access though. I have given the two roles read and write access to the app but when I check edit permission the user is only able to give access to the Everyone, User, and its own role (cirt_3).

The default.meta looks like the following:

access = read : [ admin, cirt_2, cirt_3 ], write : [ admin, cirt_2, cirt_3 ]
export = system

alt text

0 Karma


Dashboard,reports permissions are role based. If you want to give user based access, you can create different role for group of users. Correct me if I understand your requirement right?

0 Karma

Path Finder

That sounds right. I was wondering if there was a way though for a user to get access to just share objects with another group/role but not actually have access to their content.

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...