Back to Floor
The Guard Tower • Room 1

Default Roles & Capabilities

Splunk uses a role-based access control (RBAC) system. Every user is assigned one or more roles that determine what they can see and do.

The three default roles are: admin (full access), power (can create shared objects and schedule searches), and user (basic search and personal object creation).

Each role has a set of capabilities — fine-grained permissions like "edit_tcp", "list_inputs", or "schedule_search". Custom roles inherit capabilities from parent roles.

Knowledge Check

Prove your understanding to clear the room (Rewards XP)
Drag items to their correct zone (or tap item then tap zone on mobile)
Full system access and configuration
Create shared objects, schedule searches
Basic search and personal objects only
admin
power
user