Security

Role to only upload data file via the GUI

Alaza
Explorer

Hello,

I need a restrict role for only upload data file.

I add this capability :

edit_monitor - Required to make the "Add Data" option show up in the settings menu.
indexes_edit - Required to make the users index name show up in the Indexes drop down when uploading the file.
edit_tcp - Required to get the file to actually upload. Without this capability the file upload would hang.
search - Required so the user can preview the uploaded file.

 

But the settings are not visible then.

spl.PNG

The goal is to create a limited access account with only the rigth to upload data, nothing else.

Is it possible ?

 

 

Thanks for your help.

 

SPlunk version 8.1

Labels (2)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

A better solution would be to use the Universal forwarder to monitor a drop folder on a machine they can access. They can just drop data files there as needed and have it get pulled in and indexed.
Setting data inputs up including one shot uploads is more an administrative function and dangerous to give end users.

Anyhow - 

I have tried adding edit_monitor after cloning user role then I can see Add Data from settings and when I clicked on add data I can see only monitor option not upload option.

 

Screen Shot 2020-08-07 at 6.52.43 PM.png

 

Screen Shot 2020-08-07 at 6.52.01 PM.png

————————————
If this helps, give a like below.
0 Karma

Alaza
Explorer

You just copy the solution of this subject 🤔 :

https://community.splunk.com/t5/Getting-Data-In/Capability-to-upload-data-files-via-the-gui-for-a-us...

 

But it dosn't work.

0 Karma

thambisetty
SplunkTrust
SplunkTrust

Try to find the screenshot also I posted.

here we are trying to help community. 

along with the copied answer from some other post, I have tested and posted my answer also.

————————————
If this helps, give a like below.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...