Security

How would I design a role that only gives the ability to create (and search) indexes?

juniormint
Communicator

I was looking at the list of capabilities and it was not clear to me which would grant the ability to create new indexes. Could someone help me with this?

Capabilities List

0 Karma

JohnMurphyAus
Path Finder

You can add the "indexes_edit" capability to the role. This will allow a user to create and edit indexes. 

0 Karma

juniormint
Communicator

See somesoni2's comment above.

Evidently "admin_all_objects" is the only capability that enables index creation

0 Karma

somesoni2
SplunkTrust
SplunkTrust

Nothing that I know of.

0 Karma

juniormint
Communicator

Nothing more restrictive!?!

0 Karma

somesoni2
SplunkTrust
SplunkTrust

you would need "admin_all_objects" capability to the role/user in order to be able to create indexes.

0 Karma

juniormint
Communicator

Does silence mean it is not possible? Can someone ring in please.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Customer Survey!

If you use Splunk Observability Cloud, we invite you to share your valuable insights with us through a brief ...

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...

Starting With Observability: OpenTelemetry Best Practices

Tech Talk Starting With Observability: OpenTelemetry Best Practices Tuesday, October 17, 2023   |  11AM PST / ...