Security

Permission required for GUI restart of Splunk

dominiquevocat
SplunkTrust
SplunkTrust

I have a role for delegated admins containing restart_splunkd
Yet members of this role do not see the menu entry for /manager/search/control

Tags (1)
0 Karma
1 Solution

dominiquevocat
SplunkTrust
SplunkTrust

I eneded up with this role and it works fine for me...
The trick was to give admin_all_objects

authorize.conf

[role_splunk_operations]
admin_all_objects = enabled
cumulativeRTSrchJobsQuota = 0
cumulativeSrchJobsQuota = 0
edit_server = enabled
get_diag = enabled
importRoles = power
restart_splunkd = enabled
run_debug_commands = enabled
schedule_rtsearch = disabled
srchFilter = index="_*"
srchIndexesAllowed = _*
srchIndexesDefault = _*
srchMaxTime = 0

View solution in original post

0 Karma

dominiquevocat
SplunkTrust
SplunkTrust

I eneded up with this role and it works fine for me...
The trick was to give admin_all_objects

authorize.conf

[role_splunk_operations]
admin_all_objects = enabled
cumulativeRTSrchJobsQuota = 0
cumulativeSrchJobsQuota = 0
edit_server = enabled
get_diag = enabled
importRoles = power
restart_splunkd = enabled
run_debug_commands = enabled
schedule_rtsearch = disabled
srchFilter = index="_*"
srchIndexesAllowed = _*
srchIndexesDefault = _*
srchMaxTime = 0
0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...