Security

What else can you do with 'edit_scripted' capability??

robertlight
Path Finder

I have found that the capability 'edit_scripted' is required in order to use "runshellscript"

This apparently is undocumented.

What else can I do with "edit_scripted"???

0 Karma

robertlight
Path Finder

perhaps some capabilities are super-sets of edit_scripted? ie: if you have capability "X" then you don't need "edit_scripted".

I really wish someone who has access to the splunk code would weigh in here!

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

According to the authorize.conf docs, edit_scripted lets you edit scripted inputs.

runshellscript as a search command is not supported: http://docs.splunk.com/Documentation/Splunk/6.3.0/SearchReference/Runshellscript

0 Karma

robertlight
Path Finder

I constructed a role with very few capabilities and could not use runshellscript nor have one of my alerts call a shell script. I added 'edit_scripted' to my pared down role and voila everything started working.

Therefore, I'm guessing that it is a needed capability.

I would love it if someone from Splunk could actually consult the code to answer this question.

0 Karma

Yasaswy
Contributor

Hi... I am not sure if this is true for all. I have been running scripts successfully on v6.2.4 with a generic role without "edit_scripted" capability.

0 Karma
Get Updates on the Splunk Community!

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...