Security

What user role setting allows users to "Add Data"?

ddrillic
Ultra Champion

Usually we set our users in authorize.conf as -

[role_<name>_user]
importRoles = user

What needs to be added for them so they can use the Add Data feature? They only see the KNOWLEDGE section of Settings. Even the power role doesn't see it.

alt text

0 Karma
1 Solution

mwirth_splunk
Splunk Employee
Splunk Employee

Give the solution in this answer a try.
https://answers.splunk.com/answering/206281/view.html
Let me know how it goes!

View solution in original post

0 Karma

j_quickbase
Explorer

this link in the accepted solution no longer exists -- is there an updated link showing the solution?

mwirth_splunk
Splunk Employee
Splunk Employee

Give the solution in this answer a try.
https://answers.splunk.com/answering/206281/view.html
Let me know how it goes!

0 Karma

ddrillic
Ultra Champion

Wow - pretty elaborate, let me try please ...

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hi @ddrillic, This documentation explains all of the user roles and capabilities and has a page on editing roles with authorize.conf.

0 Karma

ddrillic
Ultra Champion

Thank you but I don't see the Add Data capability listed on this page...

0 Karma

ddrillic
Ultra Champion

Any thoughts on this one? ; - )

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...