Admin and user roles in Splunk App for Infrastructure
The Splunk App for Infrastructure (SAI) supports three pre-defined user roles: admin, power, and user. If you are a Splunk Cloud user, SAI supports the sc_admin role instead of the admin role. You cannot create custom roles or modify capabilities for a role in SAI.
SAI checks for pre-defined role names in a user or group. If a pre-defined role is not directly associated with a user or group, SAI doesn't recognize the capabilities for a pre-defined role. This means if you inherit a pre-defined role in a custom role, SAI doesn't recognize the capabilities of the pre-defined role in the custom role.
When logged in to SAI, the roles have the following permissions.
admin role permissions
Permitted to | Not permitted to |
---|---|
|
|
sc_admin role permissions
Ensure that each sc_admin user is assigned the sc_admin
and power
roles. To do so, log in as an sc_admin user. Follow these steps to confirm roles.
- From Splunk Web, go to Settings > Access controls.
- Click Users.
- For each sc_admin user, verify the roles In the Roles column.
- If an sc_admin user is not assigned the
power
role, click Edit for the user in the Actions column. - For Assign to roles, move the
power
role to the Selected item(s) cell. - Click Save.
An sc_admin user with the sc_admin
and power
roles has the following permissions in SAI.
Permitted to | Not permitted to |
---|---|
|
|
power role permissions
Permitted to | Not permitted to |
---|---|
|
|
user role permissions
Permitted to | Not permitted to |
---|---|
|
|
Create and modify alerts in Splunk App for Infrastructure | Manage and debug the local server in Splunk App for Infrastructure |
This documentation applies to the following versions of Splunk® App for Infrastructure (Legacy): 2.1.0, 2.1.1 Cloud only
Feedback submitted, thanks!