Splunk Enterprise Security

Difference between ES Permissions page and Splunk native edit role page

splunkreal
Motivator

Hello,

does editing ES roles on Permissions page is same as editing ES roles in Splunk's native edit role page?

I guess they both point to ES authorize.conf but native's one can work with custom roles?

Thanks.

 
* If this helps, please upvote or accept solution if it solved *
0 Karma
1 Solution

meetmshah
Contributor

Hello @splunkreal, AFAIK Yes - both the ways will update the capabilities to the respective roles as mentioned here - https://docs.splunk.com/Documentation/ES/7.3.1/Install/ConfigureUsersRoles#Add_capabilities_to_a_rol...

Please accept the solution and hit Karma, if this helps!

View solution in original post

meetmshah
Contributor

Hello @splunkreal, AFAIK Yes - both the ways will update the capabilities to the respective roles as mentioned here - https://docs.splunk.com/Documentation/ES/7.3.1/Install/ConfigureUsersRoles#Add_capabilities_to_a_rol...

Please accept the solution and hit Karma, if this helps!

meetmshah
Contributor

Hello @splunkreal, Just checking through if the issue was resolved or you have any further questions? If not, can you please accept the answer, so anyone in the future having the same question can get the solution quickly?

splunkreal
Motivator

Hello @meetmshah 

how do you add custom ES roles on Permissions page?

In data/inputs/app_permissions_manager "Action is not available" "Current instance is running SHC"

There is only ess_analyst and ess_user

Thanks.

 

* If this helps, please upvote or accept solution if it solved *
0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...