Splunk Search

Datamodel search permissions

mmoermans
Path Finder

The following search : | tstats summariesonly=t count from datamodel=Network_Traffic

Results in no results, even when giving the user permissions to all indexes. The only way to give results is to add the "User" role.
Why can't I give a custom role access to search this datamodel? The datamodel is global and so is the CIM app so I am confused why this doesn't work.

Tags (1)
0 Karma

koshyk
Super Champion

user role normally have around 16-17 capabilities attached to it.
My suggestion is you to create something like
- create new role my_user_role
- inherit all capabilities as per user at the start
- detach one by one from my_user_role
- See which is the least possible option to grant you that search (my assumption is search capability only, but not sure)

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...