Security

Import roles

nawazns5038
Builder

Hi,

I want to create a role and import capabilities or index permissions .
Suppose , I have role A which has indexes allowed = dog,cat
I create a role B and say importRoles = A and B has search indexes allowed = fish, chicken.

what index permissions does role B have in final ??
And also the capabilities ?

Will both the search indexes allowed get mixed ? or only the capabilities ??

Thanks,

0 Karma
1 Solution

prakash007
Builder

let's say you have a user=test assigned with roleB, he can search all indexes(including indexes allowed for role A)
capabilities also get mixed: you can check it under settings--->access controls---->roles---->roleB(imported capabilities are from roleA)

check this splunk doc for further explanation...
http://docs.splunk.com/Documentation/Splunk/7.2.1/Security/Addandeditroleswithauthorizeconf

View solution in original post

0 Karma

prakash007
Builder

let's say you have a user=test assigned with roleB, he can search all indexes(including indexes allowed for role A)
capabilities also get mixed: you can check it under settings--->access controls---->roles---->roleB(imported capabilities are from roleA)

check this splunk doc for further explanation...
http://docs.splunk.com/Documentation/Splunk/7.2.1/Security/Addandeditroleswithauthorizeconf

0 Karma

nawazns5038
Builder

how about for version 6.5.3 ??

0 Karma

prakash007
Builder

I don't think there is a difference in this case form 6.5.3 and 7.21...

http://docs.splunk.com/Documentation/Splunk/6.5.3/Security/Addandeditroleswithauthorizeconf

you could also test it on your local splunk instance creating a user assigning a role(with inherited role)

0 Karma

nawazns5038
Builder

Ya, it worked. Thanks for the answer !!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...