All Apps and Add-ons

Splunk On Splunk - Give access to the License Usage views to non-admin users

TONYBYERS
Path Finder

I am trying to create a non-admin user to be able to use SoS, specifically the license usage. SoS in installed in the search head where the license manager resides. I have created a role with access to _internal and _audit and that role also has read and write to the SoS and SideViews. It inherits from the 'users' role.
The user just gets "no results found" on the dashboard. If I give inherit admin and power users roles it works however I want to give minimum permissions. I am sure I'm missing a capability somewhere but I can't seem to work out which one.

I can see these being imported in to the role:
change_own_password
get_metadata
get_typeahead
input_file
list_inputs
output_file
request_remote_tok
rest_apps_view
rest_properties_get
rest_properties_set
schedule_rtsearch
search

Any ideas ?

Splunk : 6.0.3

SoS : 3.1.0

SideViews: 3.2.2

Thanks

1 Solution

TONYBYERS
Path Finder

I've got it working by adding the following capabilities to the role.

license_tab
license_edit

View solution in original post

TONYBYERS
Path Finder

I've got it working by adding the following capabilities to the role.

license_tab
license_edit

ecambra_splunk
Splunk Employee
Splunk Employee

You may also need to give the user access to the sos and sos_summary_daily indexes.

0 Karma

TONYBYERS
Path Finder

I tried that before and it didn't work. I've just tried it again to make sure and I get the same lack of data.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...