Skip to main content

Capability requirements at a glance

list_storage_passwords is the one capability most deployments need to grant: admins have it by default, ordinary user roles do not. Without it, searches fail with the missing-key error even when a key is stored, and the message says so.
list_storage_passwords exposes all of secure storage to the role, not only Kyberis keys. Grant it to purpose-built roles rather than broadly.

App object permissions

The app’s objects — commands, alert action, eventtype, lookups — are exported system-wide and readable by all roles. Write access to app objects and configuration is admin-only (admin, and sc_admin on Splunk Cloud). The setup page is therefore effectively admin-only; see Credential setup.

The cache collection ACL — do not broaden it

Cache writes go to the kyberis_ioc_cache KV Store collection, whose write ACL is admin-only by app default. This is a security property, not a convenience default: cached documents are trusted as authentic Kyberis verdicts, so any role that can write the collection could plant benign-looking results for malicious indicators — cache poisoning — that later searches, including other users’ searches, would serve as truth. Leave the write ACL alone. Non-admin searches degrade gracefully: they still get read-side cache hits and full enrichment results, and only the write-back is skipped, with one warning in the search log. If you want broader cache warming, schedule the warming search as an admin instead of widening the ACL.

What runs where

Everything runs on the search head. Both commands are search-head only (distributed = false), and the alert action executes on the search head that ran the alert. No role needs any permission on indexers beyond normal search, and only the alert action writes events, to its configured destination index.