Splunk Enterprise Security

Difference between ES Permissions page and Splunk native edit role page

splunkreal
Motivator

Hello,

does editing ES roles on Permissions page is same as editing ES roles in Splunk's native edit role page?

I guess they both point to ES authorize.conf but native's one can work with custom roles?

Thanks.

 
* If this helps, please upvote or accept solution if it solved *
0 Karma
1 Solution

meetmshah
SplunkTrust
SplunkTrust

Hello @splunkreal, AFAIK Yes - both the ways will update the capabilities to the respective roles as mentioned here - https://docs.splunk.com/Documentation/ES/7.3.1/Install/ConfigureUsersRoles#Add_capabilities_to_a_rol...

Please accept the solution and hit Karma, if this helps!

View solution in original post

meetmshah
SplunkTrust
SplunkTrust

Hello @splunkreal, AFAIK Yes - both the ways will update the capabilities to the respective roles as mentioned here - https://docs.splunk.com/Documentation/ES/7.3.1/Install/ConfigureUsersRoles#Add_capabilities_to_a_rol...

Please accept the solution and hit Karma, if this helps!

meetmshah
SplunkTrust
SplunkTrust

Hello @splunkreal, Just checking through if the issue was resolved or you have any further questions? If not, can you please accept the answer, so anyone in the future having the same question can get the solution quickly?

splunkreal
Motivator

Hello @meetmshah 

how do you add custom ES roles on Permissions page?

In data/inputs/app_permissions_manager "Action is not available" "Current instance is running SHC"

There is only ess_analyst and ess_user

Thanks.

 

* If this helps, please upvote or accept solution if it solved *
0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...