Splunk ITSI

Team has access to objects they should not have

genesiusj
Builder

Hi,

I hope someone is able to provide a solution very quickly. (Apologies). We created a team to see only certain services in the analyzer. Something changed, but we don't what. When those uses login their SA should have a filter set up; and if they were to close that filter, the other possible filters would not be seen.

That changed somehow(?). We can't go to a backup because today there have been well over 500 glass table edits (x/y position, data source, interaction, etc.) that were made.

The other issue is this team now has access to the editing Deep Dives potentially overwriting our work. Strangely, they can't edit the glass table (thankfully).

Thanks in advance for your guidance and support,
God bless,

Genesius

Labels (3)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @genesiusj 

Did you create a new role for this team? Which role(s) does their role inherit from? (e.g. itoa_team_admin)

🌟 Did this answer help you? If so, please consider:

    • Adding karma to show it was useful
    • Marking it as the solution if it resolved your issue
    • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing.

genesiusj
Builder

@livehybrid 

I gave karma, however, it was not the total solution.

I created a new role and it inherits from itoa_user, which has permissions to edit a deep dive (DD) AND overwrite it with the SAVE button. We need them to only have SAVE AS available. If I had it not inherit from itoa_user, we would have to enter/edit every required capability (time-consuming and prone to typing errors).

We also tried changing the permissions on the individual deep dives to read / no write. But the user is still able to overwrite the DD. There are other permissions issues, which I will be posting a new question.

Thanks and God bless,
Genesius

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @genesiusj 

I will work through this once I get access back to my ITSI environment and see if I can work this out for you. 

 

0 Karma

genesiusj
Builder

@livehybrid 

Not in the office now. When I created the role it worked as expected. I'll check the inheritance when I am back in the office. If so, I will create a new role without any inheritance; just hard code the permissions I want it to have. Slow, but hopefully will work.

Thanks and God bless,
Genesius

0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...