Splunk is excited to provide fine-grained authorization for Knowledge Objects starting with Saved Searches. Saved Searches are the most used Knowledge Object (KOs), and admins spend the most time delegating access to users for Saved Searches.
Today, Splunk administrators rely on a broad capability called ‘admin_all_objects’ to grant access to non-administrator users to perform admin tasks. The ‘admin_all_objects’ capability lets users access and modify any object in the system regardless of the restrictions on those objects, thus granting “full” access to Splunk KOs and configurations. A driver for this change is to let administrators delegate the management of knowledge objects (KOs) for users based on the unique roles they perform without granting full access to all KOs.
Splunk will add new capabilities for managing and delegating access to KOs. These capabilities let Splunk administrators grant fine-grained authorization to roles that let users perform administrator-level activities for the KOs. Administrators will no longer need to provide full access to Splunk resources. This helps admins adhere to the “least privilege” access principle, which reduces operational burden. The delegation of administrator-level actions for KOs to certain privileged users in turn reduces the service level objective (SLO) time to complete admin-level activities.
Many organizations that use the Splunk platform have dedicated teams which perform specific tasks that require admin-level access to certain KOs and functionality within the Splunk platform. These new capabilities empower admins to create team level admins with limited administrative access based on the role and activities defined for that team. For example, with the addition of new capabilities to manage saved searches, a team that is responsible for creating content on the Splunk platform can create and manage that content without using the 'admin_all_objects' capability. This will help the team with delegated access create content for their customer organizations without requiring super admin access, while protecting super admin bandwidth.
The three new capabilities that will unlock administrative activities related to saved searches are:
Administrators can create roles in the capabilities page and assign the roles to either a new or an existing role. The Splunk platform does not assign these capabilities to any role by default. Reserve these capabilities for high-privilege, trusted users, as they let users discover, modify, and change ownership of all saved searches. Consequently, the capabilities grant visibility to any active user that owns a saved search and any app that contains a saved search, regardless of Access Control List (ACL) permissions.
Learn more about this feature here.
Note: Only saved search owners can delete saved searches. To delete a saved search, a user with the correct permissions must reassign that saved search to themselves and then go through the search deletion workflow. These capabilities do not let users delete saved searches with no owner. Admins must still recreate the user who previously owned the object if the object is orphaned. See the Splunk documentation for more details.
Splunk continues to iterate on providing fine-grained access to knowledge objects. It is working on the following customer ideas. Also, it is working to provide administrators with the ability to further scope down the saved searches that a role with these capabilities can manage.
Splunk values your ideas and votes. Please continue to submit Splunk ideas.
Happy Splunking!
The Splunk platform removes the barriers between data and action, empowering observability, IT and security teams to ensure their organizations are secure, resilient and innovative.
Founded in 2003, Splunk is a global company — with over 7,500 employees, Splunkers have received over 1,020 patents to date and availability in 21 regions around the world — and offers an open, extensible data platform that supports shared data across any environment so that all teams in an organization can get end-to-end visibility, with context, for every interaction and business process. Build a strong data foundation with Splunk.