Security

What user role setting allows users to "Add Data"?

ddrillic
Ultra Champion

Usually we set our users in authorize.conf as -

[role_<name>_user]
importRoles = user

What needs to be added for them so they can use the Add Data feature? They only see the KNOWLEDGE section of Settings. Even the power role doesn't see it.

alt text

0 Karma
1 Solution

mwirth_splunk
Splunk Employee
Splunk Employee

Give the solution in this answer a try.
https://answers.splunk.com/answering/206281/view.html
Let me know how it goes!

View solution in original post

j_quickbase
Explorer

this link in the accepted solution no longer exists -- is there an updated link showing the solution?

mwirth_splunk
Splunk Employee
Splunk Employee

Give the solution in this answer a try.
https://answers.splunk.com/answering/206281/view.html
Let me know how it goes!

ddrillic
Ultra Champion

Wow - pretty elaborate, let me try please ...

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hi @ddrillic, This documentation explains all of the user roles and capabilities and has a page on editing roles with authorize.conf.

0 Karma

Fabian_W
Engager

I have the same question, which capabilities are needed for the "Add Data" button?

0 Karma

ddrillic
Ultra Champion

Thank you but I don't see the Add Data capability listed on this page...

0 Karma

ddrillic
Ultra Champion

Any thoughts on this one? ; - )

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...