Configure Splunk AR roles and permissions
You can grant users read or write access to deployments, notes, and playbooks in the Splunk App for AR. Note, media, and playbook permissions apply to individual notes, media, and playbooks.
Component | Read access | Write access |
---|---|---|
Deployments | Users can discover all assets and view data associated with tags, geofences, and beacons within the deployment. | Users can configure deployments and their assets, workspaces, beacons, geofences, and tags. Write access includes the ability to move panels in workspaces. |
Text notes or media | Users can view notes or media in a workspace. | Users can modify the contents of, move, or delete specific notes or media in a workspace. |
Playbooks | Users can view and run specific playbooks in a workspace. | Users can modify the contents of, move, or remove specific playbooks from the workspace. |
Default settings
The Splunk App for AR has the following default permissions settings:
- Users with the ar_admin role have read and write access to all objects.
- All objects are readable and writeable by any user unless a role for either access level has been assigned for that object.
Users must have the user role in Splunk web to view any AR data.
Permissions management
Users with the ar_admin and the ar_edit_roles capability can provide object access to other roles.
Users with the ar_edit_roles capability can only edit object access permissions for roles that they are a member of.
You can assign the ar_edit_roles capability to a user role in Splunk Web. See Add or edit a role in the Securing the Splunk Platform manual.
Settings page capabilities
Users must have the ar_admin role or the following capabilities to use the Settings tab of Splunk AR. To learn more about the Settings tab, see Configure Splunk AR.
Settings page capability | Description |
---|---|
ar_migrate_deployment_data | Users can download and import Splunk AR deployment data. To learn more about downloading and importing Splunk AR deployment data, see Migrate Splunk AR deployment data. |
edit_phantom_configuration | Users can configure a Splunk Phantom instance to use Workflow Automation with Splunk AR. To learn more about Workflow Automation, see Enable Splunk AR Workflow Automation. |
ar_manage_server_settings | Users can configure app-wide settings for the Splunk App for AR. |
Configure Splunk AR permissions
Manage Splunk AR permissions on a per-deployment basis in the Splunk App for AR.
Prerequisites
Complete the following steps before configuring Splunk AR permissions:
- Install the Splunk App for AR.
- Have the ar_admin role or the edit_roles capability.
- Make sure that the Splunk AR mobile app users are using Splunk AR version 4.0.0 or higher.
Manage permissions
- In the Splunk App for AR, navigate to the Deployments tab.
- Click the people icon.
- Assign read or write access for the whole deployment in the Deployment tab.
- Assign read or write access for workspace objects in the other tabs.
- Click Submit.
Get data into Splunk AR using a Raspberry Pi | Associate assets with dashboards in the Splunk App for AR |
This documentation applies to the following versions of Splunk® App for Edge Hub and Augmented Reality: 2.0.0, 2.0.2, 2.1.0, 3.0.0, 3.0.1, 4.0.0, 4.0.1, 4.1.1, 4.1.2, 4.2.1, 4.2.2, 4.3.0, 4.3.1, 4.4.0, 4.5.0, 4.6.0, 4.7.1, 4.8.0
Feedback submitted, thanks!