Skip to main content


Splunk Lantern

People management overview


The best practices in the people functional area focus on learning incentives and role-based access to features and data to empower users to get the most out of Splunk software. The people functional area ensures that everyone who uses Splunk has an education plan and that they earn additional access and capabilities when they advance their knowledge and experience. People best practices also ensure that each team has a safe workspace where they can experiment with new ideas and collaborate.

Follow these best practices according to the standard, intermediate, or advanced goals you have set.

Activities Standard) Intermediate Advanced

Processes to request and grant access to Splunk software from individuals or a team.

Accept ad-hoc requests (email, chat, voice)

Develop a request workflow 

Establish self-service automation that includes universal access


Criteria to determine the appropriate Splunk roles and capabilities to assign.

Utilize default roles (see Staffing a Splunk deployment and Users and Roles)

Develop custom roles that inherit capabilities hierarchically

Develop a team workspace app as the default app (see Building user group workspaces)

Develop a welcome page to help users get started (see Setting up a welcome page)

Incentivize user education with capabilities (see Enabling users with incentives)

Everything outlined in intermediate

Use roles to separate access to data from capabilities (see Managing data based on role)


How Splunk software is configured to satisfy an incoming access request.

Utilize native Splunk Enterprise authentication (see Set up native Splunk authentication)

Leverage an external directory system such as LDAP or SSO (see Setup LDAP or Configure SSO with SAML)

Use only an external directory system  (see Setup LDAP or Configure SSO with SAML)


Processes to update user and team access needs and remove users or teams when they no longer need access to Splunk software.

Utilize an IT-defined process for removing an account (see Delete a user)

Everything outlined in standard

Manage and reassign orphaned objects (see Manage orphaned knowledge objects)

Same as intermediate


Practices in place to empower end users to increase their Splunk skills and role capabilities.

Use panels in your Welcome page to direct users to relevant documentation (see Setting up a welcome page)

Everything outlined in standard

Establish Splunk education paths by role (see Setting roles and responsibilities)

Establish an incentive-based access plan (see Enabling users with incentives)

Everything outlined in intermediate

Attend Splunk policy events

Encourage users to set up their own Splunk sandbox (see Using a Splunk sandbox)