Security

how to create roles with different capabilities??

saifuddin9122
Path Finder

Hello All

i have requirement where, i have to create 2 different groups with very limited capabilities.

a role with with users who can run searches and create dashboards.
other role with users who can view the available dashboards created by role-1 users and export the logs

here is what am doing

role-1
capabilities : search,schedule_search

role-2
export_results_is_visible

am i doing it in correct way? or do i need to disable or enable any other capabilities to achieve my goal.

Thanks for the Help

0 Karma

sbbadri
Motivator

Authorize.conf

Role 1 -> role1_users and its capabilites
Role 2-> role1_users and its capabilites

Authentication.conf

if its users are in ad group:

role1_users = role1_users_ad_group
role2_users= role2_users_ad_group

if you are creating users as local users:

while creating users and select as appropriate

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...