Splunk Enterprise Security

Difference between ES Permissions page and Splunk native edit role page

splunkreal
Motivator

Hello,

does editing ES roles on Permissions page is same as editing ES roles in Splunk's native edit role page?

I guess they both point to ES authorize.conf but native's one can work with custom roles?

Thanks.

 
* If this helps, please upvote or accept solution if it solved *
0 Karma
1 Solution

meetmshah
Builder

Hello @splunkreal, AFAIK Yes - both the ways will update the capabilities to the respective roles as mentioned here - https://docs.splunk.com/Documentation/ES/7.3.1/Install/ConfigureUsersRoles#Add_capabilities_to_a_rol...

Please accept the solution and hit Karma, if this helps!

View solution in original post

meetmshah
Builder

Hello @splunkreal, AFAIK Yes - both the ways will update the capabilities to the respective roles as mentioned here - https://docs.splunk.com/Documentation/ES/7.3.1/Install/ConfigureUsersRoles#Add_capabilities_to_a_rol...

Please accept the solution and hit Karma, if this helps!

meetmshah
Builder

Hello @splunkreal, Just checking through if the issue was resolved or you have any further questions? If not, can you please accept the answer, so anyone in the future having the same question can get the solution quickly?

splunkreal
Motivator

Hello @meetmshah 

how do you add custom ES roles on Permissions page?

In data/inputs/app_permissions_manager "Action is not available" "Current instance is running SHC"

There is only ess_analyst and ess_user

Thanks.

 

* If this helps, please upvote or accept solution if it solved *
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...