Best practices for assigning permissions in team-based queues
See the following practices to best leverage team-based queue access control.
Using role-based access control with role inheritance
When using role inheritance for custom roles, it's generally a best practice to assign queue permissions to the custom role, and not the inherited role. Assigning the permissions to the custom role makes it more clear that the role itself and not the inherited capabilities have granted access. For example, if you create a role called custom_analyst_role, and inherit the capabilities from ess_analyst, assign the queue permissions to custom_analyst_role when you're managing role-based access in Splunk Enterprise Security team-based queues.
Grant customized access to team-based queues
In Splunk Enterprise Security 8.6 and higher, you can grant customized access that lets you configure permissions for each role individually, thereby providing greater access control to the queue. You also have the option to grant full access to all existing roles, including the roles that are added later.
Follow these steps to select how roles interact with the queue:
- In Splunk Enterprise Security, select Configure and then Findings and investigations.
- Select Team queues.
- Locate the queue you want to assign access for, and then expand it using the expand icon.
- Select the Roles tab.
- Select + Roles.
- In the Manage role-based access for this queue window, select Customize access to specify acceess to roles individually.
- Select Save.
- Select and deselect the check boxes to add or remove roles with access to the queue.
Alternatively, you can select Grant full access and then select Save to grant access to all existing roles. Selecting Grant full access allows you to have access to all future roles for this queue.