Splunk Enterprise

Removing write access of admin for few of the reports and alerts

vikashperiwal
Path Finder

Hi Team,

 

As part of audit question - can we remove the admin write role from few of reports and alerts...we don't want any one to do change including admin..how can we achieve this from configuration end? And also want to remove clone option from UI to all reports and alerts from configuration

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

I don’t think that you can remove that capability from admin. 
Maybe this https://community.splunk.com/t5/Dashboards-Visualizations/Hide-quot-Create-New-Dashboard-quot-Button... helps you on your second item?

r. Ismo

0 Karma

vikashperiwal
Path Finder

For reports and alerts, how to hide the clone button....when we to report and alerts we see all the reprt along that action field under that we see clone...I want to hide that /or not show...from which conf file we can achive..?

Default.meta I did not find option

0 Karma
Get Updates on the Splunk Community!

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...