The ability for many things in Splunk is controlled by capabilities applied to roles/users. In order for a user to utilize the "sendemail" command, what capabilities are necessary for their role to possess?
If there is a chart which contains search commands and the required capabilities that would suffice as well.
Hi @athoma31,
All users can access sendemail from all apps. And this applies to most of the internal commands.
For proof check command permission here - Settings > Advanced Search > Search Commands > Search for "sendemail" > Permissions.
Hope this helps!!!
Old Thread, but "list_settings" capability is required "allows a role to view server and introspection settings, such as server name and log levels. It is required for users who need to send email notifications via the sendemail"
The only requirement is that you configure Settings -> Server settings -> Email settings.
Hi @athoma31,
All users can access sendemail from all apps. And this applies to most of the internal commands.
For proof check command permission here - Settings > Advanced Search > Search Commands > Search for "sendemail" > Permissions.
Hope this helps!!!