# Assign the avl\_admin role

Use Splunk Web to assign the avl\_admin role to app administrators. See [Create and manage roles with Splunk Web](https://docs.splunk.com/Documentation/Splunk/latest/Security/Addandeditroles) in the *Securing Splunk Enterprise* manual for instructions.

{% hint style="info" %}
Assign desired roles directly to each user. Don't inherit user roles through another role.
{% endhint %}

## Customize roles <a href="#customize-roles" id="customize-roles"></a>

The following roles are available on the Anvilogic App for Splunk. See [Summary of roles and privileges](https://kevin-hwang.gitbook.io/welcome-to-anvilogic/overview/onboarding-guide/select-your-data-repository-and-get-data-in/integrate-splunk-as-your-data-repository/assign-the-avl_admin-role#summary-of-roles-and-privileges) to see a summary of the privileges provided by each role.

* avl\_admin
* avl\_senior\_developer
* avl\_developer
* avl\_senior\_triage
* avl\_triage
* avl\_readonly

You can customize the avl\_senior\_developer, avl\_developer, avl\_senior\_triage, `and` avl\_triage roles. The avl\_admin and avl\_readonly roles can't be modified.

For example, perform the following tasks to customize the capabilities allowed or restricted by the AVL Senior Developer role:

1. In the Anvilogic App for Splunk, select **Settings > App Configuration**.
2. Click **User Settings** to expand the section.
3. Click **Customize AVL Senior Developer Role** to expand the section for that role.
4. Deselect any capabilities you want to remove for this role, or select a capability to add it to the role.
5. Click **Save**.

## Summary of roles and privileges <a href="#summary-of-roles-and-privileges" id="summary-of-roles-and-privileges"></a>

The following table lists the roles in the Anvilogic App for Splunk and the privileges granted by each role. You can customize the privileges enabled for each role as desired.

<table><thead><tr><th width="297">Privilege</th><th width="114">AVL Senior Developer</th><th width="112">AVL Developer</th><th width="109">AVL Senior Triage</th><th>AVL Triage</th></tr></thead><tbody><tr><td><strong>Allowlist privileges</strong></td><td></td><td></td><td></td><td></td></tr><tr><td><a data-footnote-ref href="#user-content-fn-1">avl_add_al_rule_entry</a></td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td><a data-footnote-ref href="#user-content-fn-2">avl_remove_al_rule_entry</a></td><td>✓</td><td>✓</td><td>✓</td><td></td></tr><tr><td><a data-footnote-ref href="#user-content-fn-2">avl_modify_al_rule_entry</a></td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>avl_add_al_global_entry</td><td>✓</td><td>✓</td><td>✓</td><td></td></tr><tr><td>avl_remove_al_global_entry</td><td>✓</td><td>✓</td><td>✓</td><td></td></tr><tr><td>avl_modify_al_global_entry</td><td>✓</td><td>✓</td><td>✓</td><td></td></tr><tr><td>avl_manage_rule_al</td><td>✓</td><td>✓</td><td>✓</td><td></td></tr><tr><td>avl_manage_global_al</td><td>✓</td><td>✓</td><td>✓</td><td></td></tr><tr><td><strong>Triage privileges</strong></td><td></td><td></td><td></td><td></td></tr><tr><td>avl_change_first_alert_status</td><td></td><td></td><td></td><td>✓</td></tr><tr><td>avl_change_all_alert_status</td><td>✓</td><td>✓</td><td>✓</td><td></td></tr><tr><td>avl_change_alert_status_to_new</td><td>✓</td><td>✓</td><td>✓</td><td></td></tr><tr><td>avl_bulk_alert_status</td><td>✓</td><td>✓</td><td>✓</td><td></td></tr><tr><td>avl_add_observation</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>avl_remove_observation</td><td>✓</td><td>✓</td><td>✓</td><td></td></tr><tr><td>avl_rate_rule</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>avl_add_rule_feedback</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>avl_create_case</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>avl_suppress_alert</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>avl_suppress_global_alert</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td><strong>Content deployment privileges</strong></td><td></td><td></td><td></td><td></td></tr><tr><td>avl_deploy_content</td><td>✓</td><td></td><td></td><td></td></tr><tr><td>avl_write_hec</td><td>✓</td><td>✓</td><td>✓</td><td></td></tr><tr><td>avl_post_rest_platform</td><td>✓</td><td></td><td>✓</td><td></td></tr><tr><td>avl_post_rest</td><td>✓</td><td>✓</td><td>✓</td><td></td></tr><tr><td>avl_get_rest</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>avl_rest_config_access_get</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>avl_rest_config_access_post</td><td></td><td></td><td></td><td></td></tr></tbody></table>

## Next step

[configure-the-hec-collector-commands](https://public-docs.anvilogic.com/get-started/onboarding-guide/select-your-data-repository-and-get-data-in/integrate-splunk-as-your-data-repository/configure-the-hec-collector-commands "mention").

[^1]: Add an entry to a rule allow list.

[^2]: Remove an entry in a rule allow list.
