Add custom roles and manage capabilities in Splunk Enterprise Security
- In the Splunk platform, go to Settings.
- Select Data and then select Data inputs.
- Select App Permissions Manager and then select enforce_es_permissions.
- In the Managed Roles field, add the new custom roles as a comma separated list.
- Select Save.
ess_analyst
. For example: If you add the edit_correlationsearches
capability to the existing ess_analyst
role, an error message is displayed when a user with the ess_analyst
role attempts to save edits to a detection because detections do not have the ess_analyst
role included in their "write" ACLs.