Object permissions

Almost all objects in Splunk have permissions associated with them. These permissions essentially have the following three options:

  • Private: Only the user that created the search can see or use the object, and only in the app where it was created
  • App: All users that have permission to read an object may use that object in the context of the app that contains the object
  • Global: All users that have permission to read an object may use that object in any app

Get Implementing Splunk 7 - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.