Setting access to manager consoles and apps
The local.meta file is handy for allowing you to grant and restrict access to certain parts of your Splunk instance. For example, you can:
- Restrict users in custom roles to a specific app
- Give users in custom roles the ability to access admin level features
Granting admin roles to users
Some management abilities that belong to the Admin role are unique to that specific label. These abilities are not automatically inherited from the Admin role when you configure a role in Splunk Web or
For example, say you want to create a custom role that inherits all of the Admin abilities but has limited access to your search jobs. To do this, you would create a new role called "SpecialAdmin" and set it to inherit all of the capabilities of an Admin as described in About defining roles with capabilities then set your search limits About configuring role-based user access.
Restricting access to specific apps
local.meta file can also be used to restrict access.
For example, say you want to allow a user access to only one dashboard view. To accomplish this, you could create an app for that view and assign the user's role to that app. You should use local.meta to permit the role to view that app.
How to add and remove access via local.meta files
You can give or restrict access by editing the local.meta file to add the new role wherever you want it.
1. Locate the
local.meta file. If you are editing access for the main search page (ie, the manager controls), look in
$SPLUNK_HOME/etc/system/metadata/. If you want to edit access to a particular app, look in
$SPLUNK_HOME/etc/apps/<app_name>/metadata/. If the directory for the desired location does not contain the file, you can copy the default version
default.meta and rename it.
Note: Do NOT edit the
default.meta file directly, you may need the default values in that file at a future time.
2. In the
local.meta file, add the name of the new role to the stanza that corresponds with the desired access.
|Default stanza||What it does|
||Allow all users to read this app's contents, or access functions in the Splunk Manager page, depending on the directory you are in. Unless overridden by other metadata, allows only admin and power users to share objects into this app.|
||Determines the access controls for the Manager page access.|
3. When you have made all of your changes, restart Splunk Enterprise.
Example 1: A new role called "usermanager" only inherits capabilities from a user and has no searches or indexes inherited. The intent is to create a role that has no access to data and is solely used to create and manage user accounts.
To create this role you would edit the following stanza:
[manager/accesscontrols] access = read : [ admin ], write : [ admin ]
To include the following:
[manager/accesscontrols] access = read : [ admin, usermanager ], write : [ admin, usermanager ]
You have just given "usermanager" the ability to see and edit stuff in the "Access controls" pages in Manager.
Example 2: To enable the role "userview," to access but not edit the pages, only add the role to the read value:
[manager/accesscontrols] access = read : [ admin, userview, usermanager ], write : [ admin, usermanager ]
You can also grant access to read the manager pages to EVERY role using the wildcard:
[manager/accesscontrols] access = read : [ * ], write : [ admin ]
Example 3: You want to have a subset of users who can only read sales data that you specify. To accomplish this you can create an app for the dashboard and then create a new role "salesusers."
local.meta file in your app directory (remember that you can create one from the
default.meta file), you then edit the following stanza:
[viewstates] access = read : [ * ], write : [ * ] to read: [viewstates] access = read : [ salesusers ], write : [ admin ]
Add and edit roles with authorize.conf
Find existing users and roles
This documentation applies to the following versions of Splunk® Enterprise: 5.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.0.5, 5.0.6, 5.0.7, 5.0.8, 5.0.9, 5.0.10, 5.0.11, 5.0.12, 5.0.13, 5.0.14, 5.0.15, 5.0.16, 5.0.17, 5.0.18, 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.0.9, 6.0.10, 6.0.11, 6.0.12, 6.0.13, 6.0.14, 6.0.15, 6.1, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 6.1.8, 6.1.9, 6.1.10, 6.1.11, 6.1.12, 6.1.13, 6.1.14, 6.2.0, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.2.8, 6.2.9, 6.2.10, 6.2.11, 6.2.12, 6.2.13, 6.2.14, 6.2.15, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11, 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.5.9, 6.5.10, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.6.5, 6.6.6, 6.6.7, 6.6.8, 6.6.9, 6.6.10, 6.6.11, 6.6.12, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.0.9, 7.0.10, 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.3.0