Splunk Search

no access to search app = no transpose?

bmgilmore
Path Finder

I've run into this in two systems now, there are other commonalities so I'm not sure if this is a bug or not. If I create a user role, and take away that roles read access to the search app, those users are no longer able to run the transpose search command. I can't find any other commands that will bonk. Will do some additional testing as well but just curious if anyone else has seen this.

Thanks!

Tags (3)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Transpose is implemented as a python custom command in the search app, with global visibility meaning you can use it anywhere as long as you can see it at all. I wouldn't call it a bug, rather a quirk of the configuration hierarchy - as a quick fix you could move the command to a "commands" app that can be used by everyone.

View solution in original post

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Transpose is implemented as a python custom command in the search app, with global visibility meaning you can use it anywhere as long as you can see it at all. I wouldn't call it a bug, rather a quirk of the configuration hierarchy - as a quick fix you could move the command to a "commands" app that can be used by everyone.

0 Karma

bmgilmore
Path Finder

Thanks! Will do!

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...