Security

Import roles

nawazns5038
Builder

Hi,

I want to create a role and import capabilities or index permissions .
Suppose , I have role A which has indexes allowed = dog,cat
I create a role B and say importRoles = A and B has search indexes allowed = fish, chicken.

what index permissions does role B have in final ??
And also the capabilities ?

Will both the search indexes allowed get mixed ? or only the capabilities ??

Thanks,

0 Karma
1 Solution

prakash007
Builder

let's say you have a user=test assigned with roleB, he can search all indexes(including indexes allowed for role A)
capabilities also get mixed: you can check it under settings--->access controls---->roles---->roleB(imported capabilities are from roleA)

check this splunk doc for further explanation...
http://docs.splunk.com/Documentation/Splunk/7.2.1/Security/Addandeditroleswithauthorizeconf

View solution in original post

0 Karma

prakash007
Builder

let's say you have a user=test assigned with roleB, he can search all indexes(including indexes allowed for role A)
capabilities also get mixed: you can check it under settings--->access controls---->roles---->roleB(imported capabilities are from roleA)

check this splunk doc for further explanation...
http://docs.splunk.com/Documentation/Splunk/7.2.1/Security/Addandeditroleswithauthorizeconf

0 Karma

nawazns5038
Builder

how about for version 6.5.3 ??

0 Karma

prakash007
Builder

I don't think there is a difference in this case form 6.5.3 and 7.21...

http://docs.splunk.com/Documentation/Splunk/6.5.3/Security/Addandeditroleswithauthorizeconf

you could also test it on your local splunk instance creating a user assigning a role(with inherited role)

0 Karma

nawazns5038
Builder

Ya, it worked. Thanks for the answer !!

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...