Splunk® App for Infrastructure

Administer Splunk App for Infrastructure

Download manual as PDF

Download topic as PDF

Admin and user roles in Splunk App for Infrastructure

The Splunk App for Infrastructure (SAI) supports three pre-defined user roles: admin, power, and user. If you are a Splunk Cloud user, SAI supports the sc_admin role instead of the admin role. You cannot create custom roles or modify capabilities for a role in SAI.

When logged in to SAI, the roles have the following permissions.

admin role permissions

Permitted to Not permitted to
  • Create, read, update, delete notification settings (email, VictorOps)
  • Create, read, update, delete groups
  • Read, delete entities
  • Access and configure all Add Data pages
  • Create, read, update, delete alerts
  • Save workspaces as dashboards
  • N/A

sc_admin role permissions

Ensure that each sc_admin user is assigned the sc_admin and power roles. To do so, log in as an sc_admin user. Follow these steps to confirm roles.

  1. From Splunk Web, go to Settings > Access controls.
  2. Click Users.
  3. For each sc_admin user, verify the roles In the Roles column.
  4. If an sc_admin user is not assigned the power role, click Edit for the user in the Actions column.
  5. For Assign to roles, move the power role to the Selected item(s) cell.
  6. Click Save.

An sc_admin user with the sc_admin and power roles has the following permissions in SAI.

Permitted to Not permitted to
  • Create, read, update, delete email notification settings
  • Create, read, update, delete groups
  • Read, delete entities
  • Access and configure all Add Data pages
  • Create, read, update, delete alerts
  • Save workspaces as dashboards
  • Create, read, update, delete VictorOps notification settings

power role permissions

Permitted to Not permitted to
  • Create, read, update, delete groups
  • Read, delete entities
  • Access and configure all Add Data pages
  • Create, read, update, delete alerts
  • Save workspaces as dashboards
  • Create, read, update, delete notification settings (email, VictorOps)

user role permissions

Permitted to Not permitted to
  • Create, read, update groups
  • Read entities
  • Read alerts
  • Create, read, update, delete notification settings (email, VictorOps)
  • Delete groups
  • Delete entities
  • Access all Add Data pages
  • Create, update, delete alerts
  • Save workspaces as dashboards
PREVIOUS
Create and modify alerts in Splunk App for Infrastructure
  NEXT
Manage and debug the local server in Splunk App for Infrastructure

This documentation applies to the following versions of Splunk® App for Infrastructure: 1.3.0, 1.3.1, 1.4.0, 1.4.1


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters