Capability requirements at a glance
list_storage_passwords is the one capability most deployments need to grant:
admins have it by default, ordinary user roles do not. Without it, searches fail
with the missing-key error even when a key is stored, and the message says so.
App object permissions
The app’s objects — commands, alert action, eventtype, lookups — are exported system-wide and readable by all roles. Write access to app objects and configuration is admin-only (admin, and sc_admin on Splunk Cloud). The setup
page is therefore effectively admin-only; see
Credential setup.
The cache collection ACL — do not broaden it
Cache writes go to thekyberis_ioc_cache KV Store collection, whose write ACL
is admin-only by app default. This is a security property, not a convenience
default: cached documents are trusted as authentic Kyberis verdicts, so any
role that can write the collection could plant benign-looking results for
malicious indicators — cache poisoning — that later searches, including other
users’ searches, would serve as truth.
Leave the write ACL alone. Non-admin searches degrade gracefully: they still get
read-side cache hits and full enrichment results, and only the write-back is
skipped, with one warning in the search log. If you want broader cache warming,
schedule the warming search as an admin instead of widening the ACL.
What runs where
Everything runs on the search head. Both commands are search-head only (distributed = false), and the alert action executes on the search head that
ran the alert. No role needs any permission on indexers beyond normal search, and
only the alert action writes events, to its configured destination index..png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=66da6f97e851defcb12af05b800a8a27)
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=37df025ce7a3cc54dd90f8edad1cf54f)