Splunk Enterprise

Minimum capabilities for Splunk mpreview for Splunk users with non-admin like default user, power, power users role?

lim2
Communicator

Minimum capabilities for Splunk mpreview for Splunk users with non-admin like default user, power role and user?

Hi Everyone. I'm seeking some wisdom for minimum Splunk capabilities needed for "Splunk mpreview for Splunk users  with non-admin (with default user, power, power users) roles". created role like metrics_role with the capabilities https://docs.splunk.com/Documentation/Splunk/9.0.5/Security/Rolesandcapabilities (run_msearch, list_metrics_catalog, run_commands_ignoring_field_filter) and selected all the metrics indexes under the metrics tab and left the srchFilter/restrictions blank. Neither |mpreview index=awss3_metrics|head 9 nor |mcatalog values(metric_name) where index=awss3_metrics return any metric event. So far plan to promote usage of Splunk's metrics index hit a glitch. Would appreciate inputs at to what capabilities would be needed? Thanks in advance for your time. Bests.

Labels (1)

michaelakinneyn
Explorer
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...