Security

Import roles

nawazns5038
Builder

Hi,

I want to create a role and import capabilities or index permissions .
Suppose , I have role A which has indexes allowed = dog,cat
I create a role B and say importRoles = A and B has search indexes allowed = fish, chicken.

what index permissions does role B have in final ??
And also the capabilities ?

Will both the search indexes allowed get mixed ? or only the capabilities ??

Thanks,

0 Karma
1 Solution

prakash007
Builder

let's say you have a user=test assigned with roleB, he can search all indexes(including indexes allowed for role A)
capabilities also get mixed: you can check it under settings--->access controls---->roles---->roleB(imported capabilities are from roleA)

check this splunk doc for further explanation...
http://docs.splunk.com/Documentation/Splunk/7.2.1/Security/Addandeditroleswithauthorizeconf

View solution in original post

0 Karma

prakash007
Builder

let's say you have a user=test assigned with roleB, he can search all indexes(including indexes allowed for role A)
capabilities also get mixed: you can check it under settings--->access controls---->roles---->roleB(imported capabilities are from roleA)

check this splunk doc for further explanation...
http://docs.splunk.com/Documentation/Splunk/7.2.1/Security/Addandeditroleswithauthorizeconf

0 Karma

nawazns5038
Builder

how about for version 6.5.3 ??

0 Karma

prakash007
Builder

I don't think there is a difference in this case form 6.5.3 and 7.21...

http://docs.splunk.com/Documentation/Splunk/6.5.3/Security/Addandeditroleswithauthorizeconf

you could also test it on your local splunk instance creating a user assigning a role(with inherited role)

0 Karma

nawazns5038
Builder

Ya, it worked. Thanks for the answer !!

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...