Hello all,
Is it possible in Splunk to restrict user of accessing the "Knowledge" settings?
I want to disable certain roles to create event types.
Thank you.
i dont believe its possible to stop the user from creating their own private knowledge object however, you can restrict ability to write to the search app by disabling write permissions in the app.
manage apps>search & reporting>permissions> untick write for roles as desired.
again the user can save ko to use themselves but can not save them to the app without facing an error message.
i dont believe its possible to stop the user from creating their own private knowledge object however, you can restrict ability to write to the search app by disabling write permissions in the app.
manage apps>search & reporting>permissions> untick write for roles as desired.
again the user can save ko to use themselves but can not save them to the app without facing an error message.
Thanks, looks like this is what I need.
You can find the list of capabilities that you can turn on/off for a role, here:
http://docs.splunk.com/Documentation/Splunk/7.1.2/Security/Rolesandcapabilities#List_of_capabilities