Splunk Core Certified Advanced Power User — Question 123

Which default Splunk role could be assigned to provide users with the following capabilities?

Create saved searches -

Edit shared objects and alerts -
Not allowed to create custom roles

Answer options

Correct answer: B

Explanation

The 'power' role allows users to create saved searches and edit shared objects, which meets the requirements outlined in the question. The 'admin' role has broader permissions, including the ability to create custom roles, which is not permitted here. The 'user' role does not have the capabilities to create saved searches or edit shared objects, while the 'splunk-system-role' is reserved for system-level operations and does not fit the requirements.