Here is my role to allow a user to run a splunk health check.
[role_check_health]
cumulativeRTSrchJobsQuota = 0
cumulativeSrchJobsQuota = 0
dispatch_rest_to_indexers = enabled
edit_dist_peer = enabled
edit_health = enabled
edit_health_subset = enabled
edit_monitor = enabled
importRoles = power;user
license_tab = enabled
list_deployment_client = enabled
list_deployment_server = enabled
list_dist_peer = enabled
list_forwarders = enabled
list_health = enabled
list_health_subset = enabled
list_httpauths = enabled
list_indexer_cluster = enabled
list_indexerdiscovery = enabled
list_search_head_clustering = enabled
list_search_scheduler = enabled
list_settings = enabled
srchIndexesAllowed = _*
srchMaxTime = 0
srchTimeEarliest = -1
srchTimeWin = -1
... View more