Security

How do I grant access to the Edit Account screen for a new role?

mark_fendly
New Member

I've created a new role in the web interface and want users assigned to that role to be able to change their own passwords. I gave the role the change_own_password capability, but when the user signs in and clicks their name, and then Edit Account, they get an error. I don't see any other capabilities that sound like they grant access to that screen. Is there some setting that I'm missing?

0 Karma
1 Solution

rsennett_splunk
Splunk Employee
Splunk Employee

I'm not sure what it would be that would combine with change_own_password, but you may want to allow that role to inherit the capabilities of the lowliest user, the user role.

If there is something in the user role that offends... create a new role say my_user, with all the capability of the user role and inherit it from your new role. Then go back and remove things one by one from your my_user if they offend... checking to be sure that your new role still can edit their own account info.

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!

View solution in original post

0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

I'm not sure what it would be that would combine with change_own_password, but you may want to allow that role to inherit the capabilities of the lowliest user, the user role.

If there is something in the user role that offends... create a new role say my_user, with all the capability of the user role and inherit it from your new role. Then go back and remove things one by one from your my_user if they offend... checking to be sure that your new role still can edit their own account info.

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
0 Karma

mark_fendly
New Member

I added all of the capabilities from the user role and then removed them one by one. It looks like in addition to change_own_password I also needed both list_inputs and rest_properties_get before it would allow me to access the Edit Account screen.

0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

Ah... yes. rest_properties_get is most likely how Splunk brings back/accesses the account info... glad you got it to work.

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
Get Updates on the Splunk Community!

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...