Splunk Enterprise

Removing write access of admin for few of the reports and alerts

vikashperiwal
Path Finder

Hi Team,

 

As part of audit question - can we remove the admin write role from few of reports and alerts...we don't want any one to do change including admin..how can we achieve this from configuration end? And also want to remove clone option from UI to all reports and alerts from configuration

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

I don’t think that you can remove that capability from admin. 
Maybe this https://community.splunk.com/t5/Dashboards-Visualizations/Hide-quot-Create-New-Dashboard-quot-Button... helps you on your second item?

r. Ismo

0 Karma

vikashperiwal
Path Finder

For reports and alerts, how to hide the clone button....when we to report and alerts we see all the reprt along that action field under that we see clone...I want to hide that /or not show...from which conf file we can achive..?

Default.meta I did not find option

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...