All Apps and Add-ons

Splunk On Splunk - Give access to the License Usage views to non-admin users

TONYBYERS
Path Finder

I am trying to create a non-admin user to be able to use SoS, specifically the license usage. SoS in installed in the search head where the license manager resides. I have created a role with access to _internal and _audit and that role also has read and write to the SoS and SideViews. It inherits from the 'users' role.
The user just gets "no results found" on the dashboard. If I give inherit admin and power users roles it works however I want to give minimum permissions. I am sure I'm missing a capability somewhere but I can't seem to work out which one.

I can see these being imported in to the role:
change_own_password
get_metadata
get_typeahead
input_file
list_inputs
output_file
request_remote_tok
rest_apps_view
rest_properties_get
rest_properties_set
schedule_rtsearch
search

Any ideas ?

Splunk : 6.0.3

SoS : 3.1.0

SideViews: 3.2.2

Thanks

1 Solution

TONYBYERS
Path Finder

I've got it working by adding the following capabilities to the role.

license_tab
license_edit

View solution in original post

TONYBYERS
Path Finder

I've got it working by adding the following capabilities to the role.

license_tab
license_edit

ecambra_splunk
Splunk Employee
Splunk Employee

You may also need to give the user access to the sos and sos_summary_daily indexes.

0 Karma

TONYBYERS
Path Finder

I tried that before and it didn't work. I've just tried it again to make sure and I get the same lack of data.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...