Configure Splunk AR permissions
You can provide Splunk AR users with capabilities to view, edit, or manage objects in Splunk AR. Splunk Cloud Gateway comes with a collection of capabilities specific to Splunk AR so you can choose exactly which users have which capabilities.
Users with the admin or ar_admin role can add or remove Splunk AR capabilities.
As of Splunk Cloud Gateway version 1.9.0, the Splunk AR permissions framework has changed. Splunk AR will continue to respect the ar_write capability. Users with the ar_write capability are able to view, edit, add, or remove workspaces, beacons, and geofences. See the rest of the topic to learn how Splunk AR permissions now work.
Splunk AR capabilities
You can manage asset, workspace, note, beacon, geofence, and playbook permissions by assigning users specific Splunk AR capabilities. Each user will be able to see and associate dashboards that they have permission to view in Splunk Web.
Splunk AR comes with the following capabilities so you can manage Splunk AR permissions:
Capability | Description |
---|---|
asset_read | Users can view assets and asset groups in Splunk Cloud Gateway. They can see what data is associated with each asset. |
asset_write | Users can view and edit asset data in Splunk Cloud Gateway. They can choose what data to associate with an asset. |
asset_manage | Users can register assets, unregister assets, choose what data to associate, and move assets in and out of groups. |
workspace_read | Users can view AR workspaces and their associated data. |
workspace_write | Users can view AR workspaces, adjust visualizations, and choose what data to associate with a workspace in the Splunk AR app or Splunk Cloud Gateway. |
workspace_manage | Users can create new workspaces, delete workspaces, view AR workspaces, adjust visualizations, and choose what data to associate with a workspace in the Splunk AR app or Splunk Cloud Gateway. |
note_read | Users can view notes. |
note_write | Users can view notes and edit notes. |
note_manage | Users can view, edit, adjust, delete and create new workspace notes. |
beacon_read | Users can detect nearby beacons and see associated dashboards in the Splunk AR app. |
beacon_write | Users can associate beacons with dashboards, detect nearby beacons, and see associated dashboards in the Splunk AR app. |
beacon_manage | Users can add beacons, remove beacons, associate beacons with dashboards, detect nearby beacons, and see associated dashboards in the Splunk AR app. |
geofence_read | Users can detect nearby geofences and see associated dashboards in the Splunk AR app. |
geofence_write | Users can associate geofences with dashboards, detect nearby geofences, and see associated dashboards in the Splunk AR app. |
geofence_manage | Users can create geofences, remove geofences, associate geofences with dashboards, detect nearby geofences, and see associated dashboards in the Splunk AR app. |
playbook_read | Users can run Splunk Phantom playbooks in AR workspaces as part of the workflow automation feature. |
playbook_write | Users can edit Splunk Phantom playbooks in AR workspaces as part of the workflow automation feature. |
playbook_manage | Users can add, remove, reposition, and edit Splunk Phantom playbooks in AR workspaces as part of the workflow automation feature. |
Default permissions
By default, users with the admin role have all Splunk AR capabilities. Non-admin users have read access for all workspaces, assets, notes, beacons, and geofences.
Prerequisites
Complete the following steps before configuring AR workspace permissions:
- Have admin roll access.
- Install Splunk Cloud Gateway on your Splunk Enterprise search head.
- Enable Splunk AR in the Configure tab of Splunk Cloud Gateway. See the Install and Administer Splunk Cloud Gateway manual.
Steps
To provide users with a particular Splunk AR capability, see See Add and edit roles with Splunk Web.
If you want to allow other users the ability to add or remove Splunk AR capabilities, give them the ar_admin role.
Should I use asset tags, object detection, beacons, or geofences with Splunk AR? | Get data into Splunk AR using a Raspberry Pi |
This documentation applies to the following versions of Splunk® AR for iOS: 2.1.0, 2.2.0
Feedback submitted, thanks!