Security

How do I allow users to edit a view?

matt
Splunk Employee
Splunk Employee

If our users navigate to Manager --> Views they can see all the views, but they do not have permissions to edit or add new. What capability is required for this?

Tags (3)
1 Solution

matt
Splunk Employee
Splunk Employee

Its not so much a capability but a permission on the app. If you go to Manager » Apps » » Permissions you can give additional roles write capability which will allow them to be able to share objects with other users. If global write perms on the app are to broad your comfort you can make the write perms more granular by creating a $SPLUNK_HOME/etc/apps//metadata/local.meta file and defining the granular write capability. You can use the default.meta file in that same directory as an example of the format. You would only need to define the modified capabilities.

View solution in original post

0 Karma

matt
Splunk Employee
Splunk Employee

Its not so much a capability but a permission on the app. If you go to Manager » Apps » » Permissions you can give additional roles write capability which will allow them to be able to share objects with other users. If global write perms on the app are to broad your comfort you can make the write perms more granular by creating a $SPLUNK_HOME/etc/apps//metadata/local.meta file and defining the granular write capability. You can use the default.meta file in that same directory as an example of the format. You would only need to define the modified capabilities.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...