<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk User Permissions- Is it possible to restrict at this level? in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-User-Permissions-Is-it-possible-to-restrict-at-this-level/m-p/619608#M16439</link>
    <description>&lt;DIV&gt;Hi,&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;I have a Splunk role and the allowed index is index=api.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;There are a number of users that are part of this role.&lt;BR /&gt;&lt;BR /&gt;But I dont want to allow all users part of this role to see all logs. Only those that are relevant to them.&lt;BR /&gt;&lt;BR /&gt;These logs can be identified by a specific field called org.&lt;BR /&gt;&lt;BR /&gt;Eg. org=X org=Y org=Z (I only want specific users in this role to have access to the org field that is relevant to them)&lt;BR /&gt;&lt;BR /&gt;Is it possible to restrict this at that level? Or would we need to to create separate roles and indexes to achieve this granular access?&lt;/DIV&gt;</description>
    <pubDate>Fri, 04 Nov 2022 16:34:23 GMT</pubDate>
    <dc:creator>justindett</dc:creator>
    <dc:date>2022-11-04T16:34:23Z</dc:date>
    <item>
      <title>Splunk User Permissions- Is it possible to restrict at this level?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-User-Permissions-Is-it-possible-to-restrict-at-this-level/m-p/619608#M16439</link>
      <description>&lt;DIV&gt;Hi,&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;I have a Splunk role and the allowed index is index=api.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;There are a number of users that are part of this role.&lt;BR /&gt;&lt;BR /&gt;But I dont want to allow all users part of this role to see all logs. Only those that are relevant to them.&lt;BR /&gt;&lt;BR /&gt;These logs can be identified by a specific field called org.&lt;BR /&gt;&lt;BR /&gt;Eg. org=X org=Y org=Z (I only want specific users in this role to have access to the org field that is relevant to them)&lt;BR /&gt;&lt;BR /&gt;Is it possible to restrict this at that level? Or would we need to to create separate roles and indexes to achieve this granular access?&lt;/DIV&gt;</description>
      <pubDate>Fri, 04 Nov 2022 16:34:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-User-Permissions-Is-it-possible-to-restrict-at-this-level/m-p/619608#M16439</guid>
      <dc:creator>justindett</dc:creator>
      <dc:date>2022-11-04T16:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk User Permissions</title>
      <link>https://community.splunk.com/t5/Security/Splunk-User-Permissions-Is-it-possible-to-restrict-at-this-level/m-p/619612#M16440</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214236"&gt;@justindett&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;one question: do you want to limit the access to&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;a part of all events ((e.g. some fields but not the full _raw event) in index=api,&lt;/LI&gt;&lt;LI&gt;some events in this index (e.g. only the ones where &lt;SPAN&gt;org=X OR org=Y OR org=Z)&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;?&lt;/P&gt;&lt;P&gt;in the second case, if you want to put some limitation to the accessible events, you could add a Restriction to one role [Settings &amp;gt; Roles &amp;lt; Restriction].&lt;/P&gt;&lt;P&gt;If instead you want to pertit to some users the access only to a part of an events (e.g. some fields but not all the event), it isn't possible in general.&lt;/P&gt;&lt;P&gt;The workaround is creating a dedicated dashboard that displays only the permitted fields and "open in search" feature is disabled.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2022 09:35:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-User-Permissions-Is-it-possible-to-restrict-at-this-level/m-p/619612#M16440</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-04T09:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk User Permissions</title>
      <link>https://community.splunk.com/t5/Security/Splunk-User-Permissions-Is-it-possible-to-restrict-at-this-level/m-p/619615#M16441</link>
      <description>&lt;P&gt;Hi Guiseppe,&lt;/P&gt;&lt;P&gt;My initial response was to create dedicated dashboards as you mentioned as well. But thought perhaps someone had another idea.&lt;/P&gt;&lt;P&gt;Basically all users belong to the same role, they can see all events for index=api.&lt;/P&gt;&lt;P&gt;But the admin would like to limit access to the org field.&lt;/P&gt;&lt;P&gt;So some users can only see org=x and some can only see org=y&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2022 09:42:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-User-Permissions-Is-it-possible-to-restrict-at-this-level/m-p/619615#M16441</guid>
      <dc:creator>justindett</dc:creator>
      <dc:date>2022-11-04T09:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk User Permissions</title>
      <link>https://community.splunk.com/t5/Security/Splunk-User-Permissions-Is-it-possible-to-restrict-at-this-level/m-p/619630#M16442</link>
      <description>&lt;P&gt;Gi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214236"&gt;@justindett&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as I said, it's possible to limit the access to some filtered events of an index using Restrictions, but the only way to don't display a part of an event is to create a dedicated dashboard that displays only the fields to display and remembering to disable the "Open in search" feature that permits to see the raw events.&lt;/P&gt;&lt;P&gt;Otherwise, you could create a Summary index containing only the fields that those users can see and giving access to them to this summary index instead the full index.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2022 11:32:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-User-Permissions-Is-it-possible-to-restrict-at-this-level/m-p/619630#M16442</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-04T11:32:01Z</dc:date>
    </item>
  </channel>
</rss>

