Splunk Enterprise Security

Difference between ES Permissions page and Splunk native edit role page

splunkreal
Motivator

Hello,

does editing ES roles on Permissions page is same as editing ES roles in Splunk's native edit role page?

I guess they both point to ES authorize.conf but native's one can work with custom roles?

Thanks.

 
* If this helps, please upvote or accept solution if it solved *
0 Karma
1 Solution

meetmshah
Builder

Hello @splunkreal, AFAIK Yes - both the ways will update the capabilities to the respective roles as mentioned here - https://docs.splunk.com/Documentation/ES/7.3.1/Install/ConfigureUsersRoles#Add_capabilities_to_a_rol...

Please accept the solution and hit Karma, if this helps!

View solution in original post

meetmshah
Builder

Hello @splunkreal, AFAIK Yes - both the ways will update the capabilities to the respective roles as mentioned here - https://docs.splunk.com/Documentation/ES/7.3.1/Install/ConfigureUsersRoles#Add_capabilities_to_a_rol...

Please accept the solution and hit Karma, if this helps!

meetmshah
Builder

Hello @splunkreal, Just checking through if the issue was resolved or you have any further questions? If not, can you please accept the answer, so anyone in the future having the same question can get the solution quickly?

splunkreal
Motivator

Hello @meetmshah 

how do you add custom ES roles on Permissions page?

In data/inputs/app_permissions_manager "Action is not available" "Current instance is running SHC"

There is only ess_analyst and ess_user

Thanks.

 

* If this helps, please upvote or accept solution if it solved *
0 Karma
Get Updates on the Splunk Community!

New This Month in Splunk Observability Cloud - Metrics Usage Analytics, Enhanced K8s ...

The latest enhancements across the Splunk Observability portfolio deliver greater flexibility, better data and ...

Alerting Best Practices: How to Create Good Detectors

At their best, detectors and the alerts they trigger notify teams when applications aren’t performing as ...

Discover Powerful New Features in Splunk Cloud Platform: Enhanced Analytics, ...

Hey Splunky people! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2408. In this ...