Minimum capabilities for Splunk mpreview for Splunk users with non-admin like default user, power role and user?
Hi Everyone. I'm seeking some wisdom for minimum Splunk capabilities needed for "Splunk mpreview for Splunk users with non-admin (with default user, power, power users) roles". created role like metrics_role with the capabilities https://docs.splunk.com/Documentation/Splunk/9.0.5/Security/Rolesandcapabilities (run_msearch, list_metrics_catalog, run_commands_ignoring_field_filter) and selected all the metrics indexes under the metrics tab and left the srchFilter/restrictions blank. Neither |mpreview index=awss3_metrics|head 9 nor |mcatalog values(metric_name) where index=awss3_metrics return any metric event. So far plan to promote usage of Splunk's metrics index hit a glitch. Would appreciate inputs at to what capabilities would be needed? Thanks in advance for your time. Bests.
Requires:
run_msearch capability
Doc reference:
https://docs.splunk.com/Documentation/SplunkCloud/9.2.2403/SearchReference/Mpreview