Splunk Enterprise

Minimum capabilities for Splunk mpreview for Splunk users with non-admin like default user, power, power users role?

lim2
Communicator

Minimum capabilities for Splunk mpreview for Splunk users with non-admin like default user, power role and user?

Hi Everyone. I'm seeking some wisdom for minimum Splunk capabilities needed for "Splunk mpreview for Splunk users  with non-admin (with default user, power, power users) roles". created role like metrics_role with the capabilities https://docs.splunk.com/Documentation/Splunk/9.0.5/Security/Rolesandcapabilities (run_msearch, list_metrics_catalog, run_commands_ignoring_field_filter) and selected all the metrics indexes under the metrics tab and left the srchFilter/restrictions blank. Neither |mpreview index=awss3_metrics|head 9 nor |mcatalog values(metric_name) where index=awss3_metrics return any metric event. So far plan to promote usage of Splunk's metrics index hit a glitch. Would appreciate inputs at to what capabilities would be needed? Thanks in advance for your time. Bests.

Labels (1)

michaelakinneyn
Explorer
Tags (1)
0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...