Splunk Enterprise Security

Difference between ES Permissions page and Splunk native edit role page

splunkreal
Motivator

Hello,

does editing ES roles on Permissions page is same as editing ES roles in Splunk's native edit role page?

I guess they both point to ES authorize.conf but native's one can work with custom roles?

Thanks.

 
* If this helps, please upvote or accept solution if it solved *
0 Karma
1 Solution

meetmshah
Builder

Hello @splunkreal, AFAIK Yes - both the ways will update the capabilities to the respective roles as mentioned here - https://docs.splunk.com/Documentation/ES/7.3.1/Install/ConfigureUsersRoles#Add_capabilities_to_a_rol...

Please accept the solution and hit Karma, if this helps!

View solution in original post

meetmshah
Builder

Hello @splunkreal, AFAIK Yes - both the ways will update the capabilities to the respective roles as mentioned here - https://docs.splunk.com/Documentation/ES/7.3.1/Install/ConfigureUsersRoles#Add_capabilities_to_a_rol...

Please accept the solution and hit Karma, if this helps!

meetmshah
Builder

Hello @splunkreal, Just checking through if the issue was resolved or you have any further questions? If not, can you please accept the answer, so anyone in the future having the same question can get the solution quickly?

splunkreal
Motivator

Hello @meetmshah 

how do you add custom ES roles on Permissions page?

In data/inputs/app_permissions_manager "Action is not available" "Current instance is running SHC"

There is only ess_analyst and ess_user

Thanks.

 

* If this helps, please upvote or accept solution if it solved *
0 Karma
Get Updates on the Splunk Community!

Announcing the Expansion of the Splunk Academic Alliance Program

The Splunk Community is more than just an online forum — it’s a network of passionate users, administrators, ...

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...