- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk for Enterprise Security: Is it possible to allow non-admin users to edit and save Assets and identities lists manually?
btran
Explorer
09-14-2015
10:49 AM
I have a non-admin user "testuser" added to a non-admin "testrole"
I give testrole capabilities of edit_identitylookup, edit_lookups in capabilities.
I log in to my testuser, and I edit identity lookup file, but cannot save.
I also gave "write" permissions to testrole in the Asset and identities files.
Can a non-admin role edit the Identities and Asset files?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ekost

Splunk Employee
09-15-2015
03:50 PM
The list of custom capabilities in ES and the settings that must be changed are listed in the documentation here. Look for the "Manage Lookups" section.
