Security

How to set user permission for "Show Source" in Event Actions drop down?

baiyungao
New Member

The splunk administrator in my organization removed some permission for my role, the consequence is that I don't have permission to run "Show Source" action. Please advise, what is the configuration Item to add "View source" feature to a role permission.

0 Karma

adckia
New Member

Did you solve this issue? (The answers below don't work for me. The workflow action under Settings > Fields > Workflow actions hasn't been changed, the permissions for the action are fine, including read access for the show_source workflow action.)

0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

You need to check the workflow action under Settings > Fields > Workflow actions. Either the show_source action will have been removed, disabled, or the permissions for the action has been altered.

Normally, these default actions are Global, which is Read for Everyone, Write for admin.

You need to check (with your Splunk Admin) what this has been changed to, and ensure that a role you belong to has Read access for the show_source workflow action.

sduff_splunk
Splunk Employee
Splunk Employee

You may be able to edit the dashboard by adding "/edit" to the end of the URL.
For example,
http://localhost:8000/en-GB/app/search/test_dashboard/edit

Depending on the rights, you may need to save it under a different dashboard name

0 Karma

baiyungao
New Member

Actually I mean Event Actions - > Show Source

0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

Apologies, you were quite clear and I was in error. I've posted another solution which should address your query.

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...