Security

permissions question

Champion

Hi,

Once a view is created and made private, does a power user have the ability to change the permissions? I have some users who can't change permissions after saving the original item as private.

Tags (1)
0 Karma
1 Solution

Path Finder

Roles are implemented within Splunk with different capabilities : http://docs.splunk.com/Documentation/Splunk/6.1.1/Security/Rolesandcapabilities#List_of_available_ca...

If the power user you're talking about has the proper capability, (s)he'll be able to change Permissions.

Another possibility is to do that directly by editing the .conf files within the user's directory.

View solution in original post

Path Finder

Roles are implemented within Splunk with different capabilities : http://docs.splunk.com/Documentation/Splunk/6.1.1/Security/Rolesandcapabilities#List_of_available_ca...

If the power user you're talking about has the proper capability, (s)he'll be able to change Permissions.

Another possibility is to do that directly by editing the .conf files within the user's directory.

View solution in original post

Champion

Bingo. We implemented new roles with 6.1.1 and this user was put in a different role. All set. Thanks.

0 Karma

SplunkTrust
SplunkTrust

Does the view belong to the user who marked it private? If they didnt create the view they wont see it after they mark it private because it's private to owner not the person who marks it private.

0 Karma

SplunkTrust
SplunkTrust

I think this would reveal the permissions issue if it existed: index=_internal ( source="*splunkd.log" ) ( log_level="ERROR" )

You should see something like "file not found", "permission denied" etc.

0 Karma

SplunkTrust
SplunkTrust

My guess it's a file permissions issue:

If splunkd was running as root when the view was created. That would make the .conf file owned by root. Then if the current owner of splunkd has changed to something like splunk_daemon_service_account, splunkd wouldnt be able to edit the file.

0 Karma

Champion

He is listed as the owner, but Permissions link isn't there.

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!