We have hundreds and hundreds of saved searches and dozens of Alerts. I need the power user role to be able to edit and modify all of them. Is there a way in bulk to ensure this role has permissions without opening and editing all individually? Ie some inheritance flag to be set that trickles down such that also by default all new saved searches will be accessible to this role?
Hi @TobiasBoone,
You're looking for admin_all_objects
it's the only way to give access to all searches, reports, alerts regardless of who own them.
Morei info here :
https://docs.splunk.com/Documentation/Splunk/7.3.1/Security/Rolesandcapabilities
Be careful though as this could be too much permissions for your power users. Another way to do this would be to ensure that all newly created objects give power user the capability to write. This can be done by setting role level permission for the applications you wish your power user to edit.
Let me know if that helps.
Cheers,
David
Duplicate of: https://answers.splunk.com/answers/762969/splunk-power-users-role-edit-all-saves-reports-and.html
does admin role have access to all the saved searches and alerts?