Splunk Search

What are the minimum set of capabilities to log in to Splunk and search an index?

the_wolverine
Champion

I want to create a standalone user role to access a single index for search only. I do not want to inherit any existing role.

What are the minimum capabilities required to do this?

1 Solution

the_wolverine
Champion

It looks like these are the minimum capabilities.

get_metadata = enabled
rest_properties_get = enabled
search = enabled

View solution in original post

the_wolverine
Champion

It looks like these are the minimum capabilities.

get_metadata = enabled
rest_properties_get = enabled
search = enabled

w531t4
Path Finder

is this for web only, or api only?

0 Karma

the_wolverine
Champion

This is web and api. There is currently no distinction between the two.

0 Karma

acharlieh
Influencer

It's been a while since I've looked into things... but are you asking for members of this role to execute searches via the Splunk Web or the API only ?

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...