Security

Splunk CLI permissions and restrictions

jamesoconnell
Path Finder

Hi,

We are administering Splunk for a number of groups. One of these groups is more splunk-sophisticated and has users that are interested in using CLI commands to work directly with their splunk artifacts -- in addition to using the Web UI.

The question is how do we restrict them to using CLI just on their artifacts and not on other groups indexes, forwarders etc.

Regards,
James O'Connell

Tags (2)
0 Karma

woodcock
Esteemed Legend

As far as permissions via roles, CLI vs GUI makes no difference. Just make sure that you have the proper restrictions setup in the users' roles:

http://docs.splunk.com/Documentation/Splunk/latest/Admin/Aboutusersandroles

0 Karma

ndavis4
Explorer

In Linux it is easy enough to give users access to their own application folders/files, however, When a knowledge object is created in the GUI the ownership of that file is Splunk or Root and that user cannot modify it at the CLI. Am I missing something fundamental here?

0 Karma

woodcock
Esteemed Legend

Does this not make sense to you? That is exactly how I would have designed it: the user that is running the Splunk instance (which is usually either splunk or root) is the one that will own all of the KOs from a host-OS perspective. The GUI will allow any user who is logged in to edit his own stuff from the GUI. You can do the SAME THING with the Splunk CLI but you have to use the splunk CLI command to do it (i.e. $SPLUNK_HOME/bin/splunk add ...). As you have found, you cannot use the host OS CLI to do it by using a regular editor.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...

Index This | How many sevens are there between 1 and 100?

August 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...