Refine your search:

Hello,

is is possible to remove/disable the possibility for users to configure alerts for saved searches?

Splunk 4.1.7

Regards,

Jens

asked 15 Apr '11, 05:09

JensT's gravatar image

JensT
12417
accept rate: 25%

edited 15 Apr '11, 07:41

piebob's gravatar image

piebob ♦♦
2.4k1516


One Answer:

You can disable the 'schedule_search' capability for a role or roles in authorize.conf. By default, users in the 'user' role cannot configure alerts, but power and admin users can.

link

answered 15 Apr '11, 09:22

araitz's gravatar image

araitz ♦♦
7.0k2516
accept rate: 38%

Post your answer
toggle preview

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×197
×172
×62
×1

Asked: 15 Apr '11, 05:09

Seen: 966 times

Last updated: 15 Apr '11, 09:22

Copyright © 2005-2012 Splunk, Inc. All rights reserved.