|
I'd like to grant my Power users access to change eventtypes, savedsearches, etc. from private to app-specific/global. It seems that that is only granted to admins? |
|
You might want take a look at documentation for the authorize.conf ( http://www.splunk.com/base/Documentation/latest/Admin/Authorizeconf ). This document describes the capabilities assigned to the roles. Hmm, the only thing I see in there that may address this is: capability::admin_all_objects - but apparently that's like giving root access?
(28 Apr '11, 12:20)
nocostk
Yea, I just noticed that as well. It looks like that capability gives the user the keys to the kingdom.Not such a good idea for a power user. But it kind of make sense , you are asking to changing permissions on objects the user does not own.
(28 Apr '11, 12:30)
JSapienza
|
|
The ability to share objects into an app is controlled by the permissions on the app container. To allow power users to share eventtypes (for example) into a particular app:
|
