Roles required for the UEBA Content App for Cloud

summary of ES roles required to use the DA-ESS-UEBASecurityContent app

The following table explains the UEBA capabilities available for each Splunk Enterprise Security role that is required for this app:

Role Permissions Likely assigned to
admin Full access: activate/deactivate searches, modify configurations, view all components System administrators managing the app
sc_admin Full access: activate/deactivate searches, modify configurations, view all components Splunk Cloud administrators managing the app
ess_admin Full access: activate/deactivate searches, modify configurations, view all components Enterprise Security administrators managing the app
ess_analyst View and run searches; cannot modify configurations Security analysts reviewing data
ess_user View and run searches; cannot modify configurations Security users reviewing data