Splunk Enterprise

Minimum capabilities for Splunk mpreview for Splunk users with non-admin like default user, power, power users role?

lim2
Communicator

Minimum capabilities for Splunk mpreview for Splunk users with non-admin like default user, power role and user?

Hi Everyone. I'm seeking some wisdom for minimum Splunk capabilities needed for "Splunk mpreview for Splunk users  with non-admin (with default user, power, power users) roles". created role like metrics_role with the capabilities https://docs.splunk.com/Documentation/Splunk/9.0.5/Security/Rolesandcapabilities (run_msearch, list_metrics_catalog, run_commands_ignoring_field_filter) and selected all the metrics indexes under the metrics tab and left the srchFilter/restrictions blank. Neither |mpreview index=awss3_metrics|head 9 nor |mcatalog values(metric_name) where index=awss3_metrics return any metric event. So far plan to promote usage of Splunk's metrics index hit a glitch. Would appreciate inputs at to what capabilities would be needed? Thanks in advance for your time. Bests.

Labels (1)

michaelakinneyn
Explorer
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...