Okay, I have an open case at Splunk Support on this issue, but haven't had any activity on the case for about three weeks now. Looks like it has come to a dead end. After some discussions with several colleagues we've come to the conclusion that there are some "hidden" capabilities for the default Splunk roles, meaning that you can't just copy the capabilities from e.g. the default admin role and create a custom admin role with the same capabilities but different indexes. Sorry, this is the best answer I can give. Case closed.
... View more