Which default Splunk role is permitted to use the Log Event alert action?
The default Splunk 'power' role is granted capabilities to edit all shared knowledge objects — including saved searches and alerts — and to configure alert actions such as logging an event when an alert fires, whereas the default 'user' role is restricted to creating, running, and editing only the searches and objects that user owns. The 'can_delete' role exists solely to grant the delete-by-keyword capability used with the search command and carries no alerting capabilities. Because configuring the Log Event alert action requires the broader alert-editing capability that Splunk assigns by default to the power role (and by inheritance to admin), power is the role specifically intended to have this permission.
Community Discussion