November 2018
Beginner
298 pages
7h 51m
English
All of your custom roles and the capabilities you assign to each role are stored in an authorize.conf file that is located, by default, in $SPLUNK_HOME/etc/system /local. Some typical entries for this file might include settings to prevent a user from scheduling a real-time search (consumes a lot of resources—use sparingly), specifying a default index, and limiting which index(es) a role can access. You'll notice in the following examples that there are three general categories of entries in an authorize.conf file:
# Changes to default role settings ...
Read now
Unlock full access