Security

Import roles

nawazns5038
Builder

Hi,

I want to create a role and import capabilities or index permissions .
Suppose , I have role A which has indexes allowed = dog,cat
I create a role B and say importRoles = A and B has search indexes allowed = fish, chicken.

what index permissions does role B have in final ??
And also the capabilities ?

Will both the search indexes allowed get mixed ? or only the capabilities ??

Thanks,

0 Karma
1 Solution

prakash007
Builder

let's say you have a user=test assigned with roleB, he can search all indexes(including indexes allowed for role A)
capabilities also get mixed: you can check it under settings--->access controls---->roles---->roleB(imported capabilities are from roleA)

check this splunk doc for further explanation...
http://docs.splunk.com/Documentation/Splunk/7.2.1/Security/Addandeditroleswithauthorizeconf

View solution in original post

0 Karma

prakash007
Builder

let's say you have a user=test assigned with roleB, he can search all indexes(including indexes allowed for role A)
capabilities also get mixed: you can check it under settings--->access controls---->roles---->roleB(imported capabilities are from roleA)

check this splunk doc for further explanation...
http://docs.splunk.com/Documentation/Splunk/7.2.1/Security/Addandeditroleswithauthorizeconf

0 Karma

nawazns5038
Builder

how about for version 6.5.3 ??

0 Karma

prakash007
Builder

I don't think there is a difference in this case form 6.5.3 and 7.21...

http://docs.splunk.com/Documentation/Splunk/6.5.3/Security/Addandeditroleswithauthorizeconf

you could also test it on your local splunk instance creating a user assigning a role(with inherited role)

0 Karma

nawazns5038
Builder

Ya, it worked. Thanks for the answer !!

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...