Security

Role to only upload data file via the GUI

Alaza
Explorer

Hello,

I need a restrict role for only upload data file.

I add this capability :

edit_monitor - Required to make the "Add Data" option show up in the settings menu.
indexes_edit - Required to make the users index name show up in the Indexes drop down when uploading the file.
edit_tcp - Required to get the file to actually upload. Without this capability the file upload would hang.
search - Required so the user can preview the uploaded file.

 

But the settings are not visible then.

spl.PNG

The goal is to create a limited access account with only the rigth to upload data, nothing else.

Is it possible ?

 

 

Thanks for your help.

 

SPlunk version 8.1

Labels (2)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

A better solution would be to use the Universal forwarder to monitor a drop folder on a machine they can access. They can just drop data files there as needed and have it get pulled in and indexed.
Setting data inputs up including one shot uploads is more an administrative function and dangerous to give end users.

Anyhow - 

I have tried adding edit_monitor after cloning user role then I can see Add Data from settings and when I clicked on add data I can see only monitor option not upload option.

 

Screen Shot 2020-08-07 at 6.52.43 PM.png

 

Screen Shot 2020-08-07 at 6.52.01 PM.png

————————————
If this helps, give a like below.
0 Karma

Alaza
Explorer

You just copy the solution of this subject 🤔 :

https://community.splunk.com/t5/Getting-Data-In/Capability-to-upload-data-files-via-the-gui-for-a-us...

 

But it dosn't work.

0 Karma

thambisetty
SplunkTrust
SplunkTrust

Try to find the screenshot also I posted.

here we are trying to help community. 

along with the copied answer from some other post, I have tested and posted my answer also.

————————————
If this helps, give a like below.
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...