Security

permissions question

a212830
Champion

Hi,

Once a view is created and made private, does a power user have the ability to change the permissions? I have some users who can't change permissions after saving the original item as private.

Tags (1)
0 Karma
1 Solution

ofrachon
Path Finder

Roles are implemented within Splunk with different capabilities : http://docs.splunk.com/Documentation/Splunk/6.1.1/Security/Rolesandcapabilities#List_of_available_ca...

If the power user you're talking about has the proper capability, (s)he'll be able to change Permissions.

Another possibility is to do that directly by editing the .conf files within the user's directory.

View solution in original post

ofrachon
Path Finder

Roles are implemented within Splunk with different capabilities : http://docs.splunk.com/Documentation/Splunk/6.1.1/Security/Rolesandcapabilities#List_of_available_ca...

If the power user you're talking about has the proper capability, (s)he'll be able to change Permissions.

Another possibility is to do that directly by editing the .conf files within the user's directory.

a212830
Champion

Bingo. We implemented new roles with 6.1.1 and this user was put in a different role. All set. Thanks.

0 Karma

jkat54
SplunkTrust
SplunkTrust

Does the view belong to the user who marked it private? If they didnt create the view they wont see it after they mark it private because it's private to owner not the person who marks it private.

0 Karma

jkat54
SplunkTrust
SplunkTrust

I think this would reveal the permissions issue if it existed: index=_internal ( source="*splunkd.log" ) ( log_level="ERROR" )

You should see something like "file not found", "permission denied" etc.

0 Karma

jkat54
SplunkTrust
SplunkTrust

My guess it's a file permissions issue:

If splunkd was running as root when the view was created. That would make the .conf file owned by root. Then if the current owner of splunkd has changed to something like splunk_daemon_service_account, splunkd wouldnt be able to edit the file.

0 Karma

a212830
Champion

He is listed as the owner, but Permissions link isn't there.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...