Hi fellow Splunkers,
I am looking for a way to restrict access to certain alert scripts if possible.
Is there a way to restrict access to alert scripts at all?
Thank you,
J
Hello,
user role by default doesn't have the ability to create Alerts (So good here!). However, power and above can send Alerts by design. If you want to restrict a specific script action, your best best is to put it under
/opt/splunk/etc/apps/My_new_app/bin/scripts. And limit the app's access to admin only.
Hope this helps!
Thanks,
Raghav