Splunk Cloud Platform

permissions

chen
Observer

I added the 'edit user' capability but retrieved only one user from this URL:

/services/authentication/users
 

However, when I added 'power user' permissions, I was able to access most of the users. Could you please clarify what the minimum permissions are to retrieve all users?

Additionally, I encountered a similar issue with the URL for fetching triggered alerts:

/services/alerts/fired_alerts/{ALERT_NAME}
 

What permissions are necessary for accessing this information?

Thanks

0 Karma

marnall
Motivator

You also need the list_all_users capability in your role, to list all users.

For the alerts, your user needs permission to read the alert to fetch triggered alerts.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...