<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restricting user access to specific fields in index in Security</title>
    <link>https://community.splunk.com/t5/Security/How-to-restrict-user-access-to-specific-fields-in-index/m-p/598273#M16105</link>
    <description>&lt;P&gt;Even though &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt; pointed you to the functionality, I simply wouldn't trust it to do the task properly.&lt;/P&gt;&lt;P&gt;Whenever you have access to the _raw event, you can always see the contents of the original event and you can extract the field in any other way so it's kinda "security by obscurity" approach.&lt;/P&gt;&lt;P&gt;It's safer to assume that if the data is ingested and indexed in Splunk, it's available for reading to anyone with access to relevant index.&lt;/P&gt;&lt;P&gt;The fieldfilter approach could work relatively well in some specific use cases (severely limited users with no access to "raw" search, just clicking through some pre-defined dashboards).&lt;/P&gt;</description>
    <pubDate>Wed, 18 May 2022 09:10:35 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2022-05-18T09:10:35Z</dc:date>
    <item>
      <title>How to restrict user access to specific fields in index</title>
      <link>https://community.splunk.com/t5/Security/How-to-restrict-user-access-to-specific-fields-in-index/m-p/597501#M16090</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am currently running Splunk 8.1.9&lt;/P&gt;
&lt;P&gt;Is it possible to create a role, that will allow a user to access only specific fields in an index?&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;P&gt;field1, field2, field3, field4, field5&lt;/P&gt;
&lt;P&gt;User have access to the index, but can only view data in field1, field4 and field5.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Much thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 15:12:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-restrict-user-access-to-specific-fields-in-index/m-p/597501#M16090</guid>
      <dc:creator>madcow</dc:creator>
      <dc:date>2022-05-18T15:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting user access to specific fields in index</title>
      <link>https://community.splunk.com/t5/Security/How-to-restrict-user-access-to-specific-fields-in-index/m-p/597522#M16091</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I think that this feature has published some time ago. Haven't try it by myself, but at least here is some documentation about it.&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/8.2.2202/Security/planfieldfiltering" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/8.2.2202/Security/planfieldfiltering&lt;/A&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 06:46:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-restrict-user-access-to-specific-fields-in-index/m-p/597522#M16091</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-05-12T06:46:04Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting user access to specific fields in index</title>
      <link>https://community.splunk.com/t5/Security/How-to-restrict-user-access-to-specific-fields-in-index/m-p/598266#M16104</link>
      <description>&lt;P&gt;Hi isoutamo,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks, I followed the documentation (&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/8.2.2202/Security/setfieldfiltering" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/8.2.2202/Security/setfieldfiltering&lt;/A&gt;) and it doesn't seem to work.&lt;/P&gt;&lt;P&gt;[role_limited]&lt;/P&gt;&lt;P&gt;fieldFilter-field2 = XXXX&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I restarted Splunk after making the changes, but the user with the assigned "limited" role was still able to see data in field2 in clear.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 08:52:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-restrict-user-access-to-specific-fields-in-index/m-p/598266#M16104</guid>
      <dc:creator>madcow</dc:creator>
      <dc:date>2022-05-18T08:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting user access to specific fields in index</title>
      <link>https://community.splunk.com/t5/Security/How-to-restrict-user-access-to-specific-fields-in-index/m-p/598273#M16105</link>
      <description>&lt;P&gt;Even though &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt; pointed you to the functionality, I simply wouldn't trust it to do the task properly.&lt;/P&gt;&lt;P&gt;Whenever you have access to the _raw event, you can always see the contents of the original event and you can extract the field in any other way so it's kinda "security by obscurity" approach.&lt;/P&gt;&lt;P&gt;It's safer to assume that if the data is ingested and indexed in Splunk, it's available for reading to anyone with access to relevant index.&lt;/P&gt;&lt;P&gt;The fieldfilter approach could work relatively well in some specific use cases (severely limited users with no access to "raw" search, just clicking through some pre-defined dashboards).&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 09:10:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-restrict-user-access-to-specific-fields-in-index/m-p/598273#M16105</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-05-18T09:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting user access to specific fields in index</title>
      <link>https://community.splunk.com/t5/Security/How-to-restrict-user-access-to-specific-fields-in-index/m-p/598323#M16106</link>
      <description>&lt;P&gt;I totally agree with&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;that these somehow search filter related "features" are not something what I can propose or even use by myself. Usually if you can access _raw you can always access that data somehow.&lt;/P&gt;&lt;P&gt;Better option is forward those events e.g. in two different indexes or other way "physically" separate those behind different roles/access.&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 14:54:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-restrict-user-access-to-specific-fields-in-index/m-p/598323#M16106</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-05-18T14:54:55Z</dc:date>
    </item>
  </channel>
</rss>

