Splunk Enterprise Security

Custom Role Inheritance Is Not Working In ES App After Upgrade

rsantoso_splunk
Splunk Employee
Splunk Employee

Customer have created SOC l1 and SOCl 2 custom roles, SOC l1 has the inherited role ES analyst, ES user and user.

SOC l2 inherited role SOC l1 and few additional capabilities. There was no issue with 4.7.X version. SOCl2 person can edit the notable event and investigated all logs etc. After upgrade SOCl2 started facing issue, user unable to edit the notable event.

In customer test environment once customer remove our custom role from SOCl2 and add ES analyst, ES user and user role then it start working. What customer see custom inheritance of role is not working. Can assist to understand what is the reason behind this?

0 Karma
1 Solution

rsantoso_splunk
Splunk Employee
Splunk Employee

It is a bug SOLNESS-17285 with the ES version 5.1.1, where the cannot handle multi-level inheritance.

This bug target to be fix in next release 5.3.

The workaround for the customer will be that SOC2 inherits from es-analyst directly rather than from SOC1.

View solution in original post

0 Karma

rsantoso_splunk
Splunk Employee
Splunk Employee

It is a bug SOLNESS-17285 with the ES version 5.1.1, where the cannot handle multi-level inheritance.

This bug target to be fix in next release 5.3.

The workaround for the customer will be that SOC2 inherits from es-analyst directly rather than from SOC1.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...