I've been setting up SplunkLightand I'm unable to create new users. When I go to system > manage accounts under the admin account, I don't get an option to createadditional accounts (see a...
Hi, I wonder whether someone may be able to help me please.
I'm using the search below to extract the date when Splunkuseraccounts have been created:
index=_audit action=edit_user o...
...olutions to this is…
• Give Splunk_Marvel the role “dc_events” …but now Steve and Peter are not supposed to see the index “identity” and Tony shouldn’t see “Powers”
• Createa new SAML/AD group t...
Hey Guys!
I want to be able to createauseraccount, that has only one capability (the edit_user), so that whenever someone forgets their password, they can log in to this useraccountand not b...
Hi, I'd like the users to not be able to createany new dashboards either from the search bar or the "Create New Dashboard" button on the dashboard's page. Only the admin users should be a...
All,
I want to create dedicated admin accounts for users so they are not running as admin, except when needed. However our Active Directory team will only issue 1 AD account per user. I thought t...
...hanged the ownership to for /opt/splunk to the user "Splunk" that I've created because I was told it was bad to run Splunkas root. When working in my "Splunk" useraccount I continuously get t...
I'm running Splunk Enterprise 8.2.4. When deploying the Universal Forwarder for Windows (version 8.2.4) and selecting to run it under the Local System account it subsequently asks me for the 'create...
I copied the log from splunk to regex101.com. I am searching against Windows Event Viewer logs. Event Code 4722 and 4720. I am trying to createa new field. I am trying to createa new field 'e...