What Capabilities is needed to Create Identity Management for Data Enrichment in ES

New Member

When I wanted to create a new lookup in ES through ES->Configure->Data Enrichment->Identity Management, there's no "New" button, the role we are using is ess_admin, from the documentation, "edit_identitylookup" is the capability should be granted, but I've already include that capability into the role. Any other capabilities do we have to grant to the role?


Tags (1)
0 Karma


I'm not too sure about the specific roles you require but when I created my identity list in Splunk ES I followed the following steps:

I was also ESS_admin when I done this so that role should be enough I would think.

If this doesn't help you then any further info on your problem might help in trying to assist you.


0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!