Is it possible in Splunk to restrict user of accessing the "Knowledge" settings?
I want to disable certain roles to create event types.
i dont believe its possible to stop the user from creating their own private knowledge object however, you can restrict ability to write to the search app by disabling write permissions in the app.
manage apps>search & reporting>permissions> untick write for roles as desired.
again the user can save ko to use themselves but can not save them to the app without facing an error message.
View solution in original post
Thanks, looks like this is what I need.
You can find the list of capabilities that you can turn on/off for a role, here: