Splunk Search

Dashboard panels: what's the proper use of the splunk admin_all_objects capability vs. read permission settings?

kteng2024
Path Finder

When I give admin_all_objects to a role, that role can also edit the permissions of the dashboards, but when I remove this capability, some of the dashboards are not working because of the field extraction and lookup, despite having global permissions. So, is there any way to remove the "edit permissions" by giving the admin_all_objects to a role?

0 Karma

somesoni2
Revered Legend

Apart from scope being global, you need to ensure that your role has read permissions on those field extractions/lookups. Once you fix the permissions, you don't need admin_all_objects capability to be given, and still all dashboards works.

0 Karma

DalJeanis
Legend

Yes.

Admin_all_objects is giving the user the keys to the car, the combo to the safe, a book of blank checks, an unlimited congressional spending account, and a case of rum.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...