All Apps and Add-ons

Splunk On Splunk - Give access to the License Usage views to non-admin users

TONYBYERS
Path Finder

I am trying to create a non-admin user to be able to use SoS, specifically the license usage. SoS in installed in the search head where the license manager resides. I have created a role with access to _internal and _audit and that role also has read and write to the SoS and SideViews. It inherits from the 'users' role.
The user just gets "no results found" on the dashboard. If I give inherit admin and power users roles it works however I want to give minimum permissions. I am sure I'm missing a capability somewhere but I can't seem to work out which one.

I can see these being imported in to the role:
change_own_password
get_metadata
get_typeahead
input_file
list_inputs
output_file
request_remote_tok
rest_apps_view
rest_properties_get
rest_properties_set
schedule_rtsearch
search

Any ideas ?

Splunk : 6.0.3

SoS : 3.1.0

SideViews: 3.2.2

Thanks

1 Solution

TONYBYERS
Path Finder

I've got it working by adding the following capabilities to the role.

license_tab
license_edit

View solution in original post

TONYBYERS
Path Finder

I've got it working by adding the following capabilities to the role.

license_tab
license_edit

ecambra_splunk
Splunk Employee
Splunk Employee

You may also need to give the user access to the sos and sos_summary_daily indexes.

0 Karma

TONYBYERS
Path Finder

I tried that before and it didn't work. I've just tried it again to make sure and I get the same lack of data.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...
OSZAR »