Security

Share a saved search without admin rights?

wegordoniii
Engager

I have a group of splunk users that need to be able to create & share queries with one another. Unlike the older version of splunk, when a user saves a search it's made private and they aren't given an option to share it with others. The documentation on sharing saved searches assumes that you're an Administrator, but I need users without the Administrative role to be able to share saved searches.

Is it possible for a non-admin Splunk User to share a saved search with other non-admin Splunk Users without the intervention of a Splunk Administrator?

Thank you

1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Yes they can, if they have "write" permissions to the app that they want to make it visible/shareable within.

View solution in original post

woodcock
Esteemed Legend
0 Karma

tuinteractive
Engager

no written docs sadly, but I was able to get some good info from support on this. the "write" bit for a user/role on the search app just lets them then modify attribute for their search. so lets them share their searches for example.

the user then can control on a given search who they want to read/write THAT search. read on the search lets folks run it. write let's them modify it.

So an example. say you have Bob,Mary in Role1, Joe,Gary in Role2. giving Role1,Role2 write access to "search app" just let's them share their objects. it does not give them global "write" access to ALL of search. which is I think the concern wegordoniii and wrangler2x had (as did we).

Then if Bob shares search SearchA with read to Role1,Role2. then all four users can run it. but only Bob can maintain/modify the search itself.

If Joe makes a SearchB and marks id read for Role1 and read&write for Role2 then:
- Bob and Mary will be able to just run the search
- Joe,Gary will be able to both make changes to the search.

gkanapathy
Splunk Employee
Splunk Employee

Yes they can, if they have "write" permissions to the app that they want to make it visible/shareable within.

wrangler2x
Motivator

I'd like to know the answer to this last question also. What are the security implications of that?

wegordoniii
Engager

Excellent; thank you!

Is there documentation describing all of the consequences of giving a user write permission to the search App? I want to be aware of any security implications that this change might incur.

TIA

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...