Security

permissions question

a212830
Champion

Hi,

Once a view is created and made private, does a power user have the ability to change the permissions? I have some users who can't change permissions after saving the original item as private.

Tags (1)
0 Karma
1 Solution

ofrachon
Path Finder

Roles are implemented within Splunk with different capabilities : http://docs.splunk.com/Documentation/Splunk/6.1.1/Security/Rolesandcapabilities#List_of_available_ca...

If the power user you're talking about has the proper capability, (s)he'll be able to change Permissions.

Another possibility is to do that directly by editing the .conf files within the user's directory.

View solution in original post

ofrachon
Path Finder

Roles are implemented within Splunk with different capabilities : http://docs.splunk.com/Documentation/Splunk/6.1.1/Security/Rolesandcapabilities#List_of_available_ca...

If the power user you're talking about has the proper capability, (s)he'll be able to change Permissions.

Another possibility is to do that directly by editing the .conf files within the user's directory.

a212830
Champion

Bingo. We implemented new roles with 6.1.1 and this user was put in a different role. All set. Thanks.

0 Karma

jkat54
SplunkTrust
SplunkTrust

Does the view belong to the user who marked it private? If they didnt create the view they wont see it after they mark it private because it's private to owner not the person who marks it private.

0 Karma

jkat54
SplunkTrust
SplunkTrust

I think this would reveal the permissions issue if it existed: index=_internal ( source="*splunkd.log" ) ( log_level="ERROR" )

You should see something like "file not found", "permission denied" etc.

0 Karma

jkat54
SplunkTrust
SplunkTrust

My guess it's a file permissions issue:

If splunkd was running as root when the view was created. That would make the .conf file owned by root. Then if the current owner of splunkd has changed to something like splunk_daemon_service_account, splunkd wouldnt be able to edit the file.

0 Karma

a212830
Champion

He is listed as the owner, but Permissions link isn't there.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...