Configure role based access control inside Splunk apps
Splunk SOAR (On-premises) supports granular asset access control inside of Splunk SOAR (On-premises) apps to ensure that only authorized access to the app is allowed. Asset access control works on an authorized basis, with a default-deny policy.
When granular asset access control is enabled, only users or groups with explicit permissions are able to perform actions in a Splunk SOAR (On-premises) app. Configure user and group permissions on all configured apps before enabling granular asset access control.
To set up a single user to have access the "lookup domain" action on the Google DNS asset:
- From the Home menu, select Apps.
- Click 1 configured asset to expand the section.
- Click Google DNS to edit the asset.
- Click the Access Control tab.
- Click Edit.
- Select lookup domain from the App Action drop-down list.
- Select the user desired user name then click the right arrow in order to move the user from the Users and Roles list into the Approved Users and Roles list.
- Click Save.
Now enable granular asset access control so that the permission set above takes effect.
- From the Home menu, select Administration.
- Select User Management > Asset Permissions.
- Check the Enable granular Asset Access Control checkbox.
- Confirm that you want to change global asset permissions.
- Click Save Changes.