<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to limit access to users own data. in Security</title>
    <link>https://community.splunk.com/t5/Security/How-to-limit-access-to-users-own-data/m-p/619841#M16446</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/36534"&gt;@las&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you have to create two (or more) roles dividing the users betweeen them and creating a restriction for one of these roles.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 07 Nov 2022 10:33:22 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-11-07T10:33:22Z</dc:date>
    <item>
      <title>How to limit access to users own data?</title>
      <link>https://community.splunk.com/t5/Security/How-to-limit-access-to-users-own-data/m-p/619406#M16435</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;
&lt;P&gt;We are going to have a datasource with some sensitive data, where there is a requirement, that only the owner of a specific event is allowed to see it.&lt;/P&gt;
&lt;P&gt;The events will have the user as part of the data, that field can be created as an indexed field.&lt;/P&gt;
&lt;P&gt;I will, of course, have the data in a separate index, and thought I might be able to use restriction to limit access so that the user only can search in data where the field user matches the logged on user.&lt;/P&gt;
&lt;P&gt;I can see it is possible to use the token $env.user$ in a dashboard, but I would really like to use it in the restrictions part of the role, so it automatically will use the logged on user in the restriction.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help will be much appreciated.&lt;/P&gt;
&lt;P&gt;Kind regards&lt;/P&gt;
&lt;P&gt;las&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 14:16:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-limit-access-to-users-own-data/m-p/619406#M16435</guid>
      <dc:creator>las</dc:creator>
      <dc:date>2022-11-03T14:16:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit access to users own data.</title>
      <link>https://community.splunk.com/t5/Security/How-to-limit-access-to-users-own-data/m-p/619411#M16436</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/36534"&gt;@las&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;for my knowledge a user can access the full events in an index and it isn't possible to eneble view of only a part of an event.&lt;/P&gt;&lt;P&gt;The only solution is a workaround:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;define a new role, adding the user with limited data access,&lt;/LI&gt;&lt;LI&gt;create a summary index containng only the information that the user can see,&lt;/LI&gt;&lt;LI&gt;enable the above new role to access the summary index,&lt;/LI&gt;&lt;LI&gt;create a dashboard for the user accessing the Summary index.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 07:19:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-limit-access-to-users-own-data/m-p/619411#M16436</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-03T07:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit access to users own data.</title>
      <link>https://community.splunk.com/t5/Security/How-to-limit-access-to-users-own-data/m-p/619838#M16445</link>
      <description>&lt;P&gt;Hi Guiseppe.&lt;/P&gt;&lt;P&gt;I might have expressed myself a littele clumsy, I do not want the users to see part of an event, but only a subset of events in the index.&lt;/P&gt;&lt;P&gt;There is functionality available to limit searches using indexed fields (Restrictions), so the question is really, how do I get the user that is logged on into this role.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;las&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 10:31:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-limit-access-to-users-own-data/m-p/619838#M16445</guid>
      <dc:creator>las</dc:creator>
      <dc:date>2022-11-07T10:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit access to users own data.</title>
      <link>https://community.splunk.com/t5/Security/How-to-limit-access-to-users-own-data/m-p/619841#M16446</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/36534"&gt;@las&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you have to create two (or more) roles dividing the users betweeen them and creating a restriction for one of these roles.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 10:33:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-limit-access-to-users-own-data/m-p/619841#M16446</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-07T10:33:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit access to users own data.</title>
      <link>https://community.splunk.com/t5/Security/How-to-limit-access-to-users-own-data/m-p/619864#M16447</link>
      <description>&lt;P&gt;Hi Guiseppe.&lt;/P&gt;&lt;P&gt;Yes, the question is if I can make the restriction dynamic based on the user that is logged in?&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;las&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 11:39:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-limit-access-to-users-own-data/m-p/619864#M16447</guid>
      <dc:creator>las</dc:creator>
      <dc:date>2022-11-07T11:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit access to users own data.</title>
      <link>https://community.splunk.com/t5/Security/How-to-limit-access-to-users-own-data/m-p/619875#M16448</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/36534"&gt;@las&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;yes it's possible assigning the user to a role, then you give to each role the correct restrictions, but anyway the management is done using roles.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 12:46:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-to-limit-access-to-users-own-data/m-p/619875#M16448</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-11-07T12:46:43Z</dc:date>
    </item>
  </channel>
</rss>

