Reporting

Permission issue in Alerts created in Search & Reporting App

anandhalagarasa
Path Finder

In Splunk Cloud a user (A) has created multiple alerts (around 50+ alerts) in the Search & Reporting App and he has been assigned as an admin role. Similarly a same guy from his team (B) has been assigned to the same role (admin) but he cant able to edit the search which has been created by (A) and the only option it is available for him is "Clone" or "Embed".

So in a single shot can we able to change the permissions for all the alerts which has been created by (A) user so that (B) can able to edit or write the search query.

I navigated to Manage Apps and checked into "Search & Reporting App" and then i have provided the write permission for the admins and saved it and also reloaded the authentication but still (B) user cant able to edit the query which has been created by (A).

So is there any way to change the write permissions in one shot for the alerts which has been created in the "Search & Reporting App" by (A) so that (B) can able to modify the query and save it.

Tags (1)
0 Karma

anandhalagarasa
Path Finder

Kindly help on this request.

0 Karma

anandhalagarasa
Path Finder

Can anyone help on the request

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...