capability

noun

A user action within Splunk that can be restricted through role-based security, such as "editing saved searches" or "changing default input settings." Capabilities are are associated with specific roles and granular access controls in Splunk.

authorize.conf provides a listing of all available Splunk capabilities.

For more information

In the Admin manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time