Splunk ITSI

Team has access to objects they should not have

genesiusj
Builder

Hi,

I hope someone is able to provide a solution very quickly. (Apologies). We created a team to see only certain services in the analyzer. Something changed, but we don't what. When those uses login their SA should have a filter set up; and if they were to close that filter, the other possible filters would not be seen.

That changed somehow(?). We can't go to a backup because today there have been well over 500 glass table edits (x/y position, data source, interaction, etc.) that were made.

The other issue is this team now has access to the editing Deep Dives potentially overwriting our work. Strangely, they can't edit the glass table (thankfully).

Thanks in advance for your guidance and support,
God bless,

Genesius

Labels (3)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @genesiusj 

Did you create a new role for this team? Which role(s) does their role inherit from? (e.g. itoa_team_admin)

🌟 Did this answer help you? If so, please consider:

    • Adding karma to show it was useful
    • Marking it as the solution if it resolved your issue
    • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing.

genesiusj
Builder

@livehybrid 

I gave karma, however, it was not the total solution.

I created a new role and it inherits from itoa_user, which has permissions to edit a deep dive (DD) AND overwrite it with the SAVE button. We need them to only have SAVE AS available. If I had it not inherit from itoa_user, we would have to enter/edit every required capability (time-consuming and prone to typing errors).

We also tried changing the permissions on the individual deep dives to read / no write. But the user is still able to overwrite the DD. There are other permissions issues, which I will be posting a new question.

Thanks and God bless,
Genesius

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @genesiusj 

I will work through this once I get access back to my ITSI environment and see if I can work this out for you. 

 

0 Karma

genesiusj
Builder

@livehybrid 

Not in the office now. When I created the role it worked as expected. I'll check the inheritance when I am back in the office. If so, I will create a new role without any inheritance; just hard code the permissions I want it to have. Slow, but hopefully will work.

Thanks and God bless,
Genesius

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...