Security

Is there a way to unimport roles or disable capabilities for a certain role?

the_wolverine
Champion

Is there a way to unimportRoles or disable capabilities for a certain role? I don't believe so based on the documentation:

[role_<roleName>]
<capability> = <enabled>
...
    * Roles inherit all capabilities from imported roles, and inherited
      capabilities cannot be disabled.
...

importRoles = <string>
* Semicolon delimited list of other roles and their associated capabilities
  that should be imported.
* Importing other roles also imports the other aspects of that role, such as
  allowed indexes to search.

We would like to create a custom role to override inherited capabilities. An example would be a system account which has less capabilities but has inherited user role capabilities. Right now it seems like an RFE.

0 Karma

phadnett_splunk
Splunk Employee
Splunk Employee

One solution might be to create a new role (ie. user-system) with fewer capabilities than the normal 'user' role. Then have your 'system-account' role inherit this new 'user-system' role along with the capabilities assigned to it.

Is this what you are looking to achieve?

0 Karma

the_wolverine
Champion

Thanks for your response but this is not what I'm looking for. Since group membership allows a group owner to add their system-account to their own group, the system-account then inherits user capabilities. Even if I find out about the system-account and drop it into a system-account-role, it doesn't uninherit the capabilities already granted by a user role.

This is why I am looking for a way to uninherit or disable capabilities.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...