<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I restrict a user to only search a specific set of peers in our Splunk Enterprise environment? in Security</title>
    <link>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129715#M3929</link>
    <description>&lt;P&gt;It should be noted that there is a bug (well I think its a bug) with using search filters and roles.&lt;/P&gt;

&lt;P&gt;It has a weird behavior unlike any other setting in splunk.&lt;/P&gt;

&lt;P&gt;If you use any sort of imported role which has search filter, it will NOT be applied IF your current role doesn't explicitly state a search filter option, If you DO include it then it will &lt;STRONG&gt;stack&lt;/STRONG&gt; the filters together and not apply the highest level precedence stanza (ie. the normal operation for every single other stanza in splunk).&lt;/P&gt;

&lt;P&gt;ie. a broken configuration :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;role_user 
 srchFilter = splunk_server=server_1

role_custom_user 
import_role = user
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I found this issue when trying to apply a filter to roles all of which inherited admin/power or user roles.&lt;BR /&gt;
You have to explicitly give every role a filter unfortunately which makes inheritence useless. I had to manually add the filter for 300+ roles &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 24 Apr 2015 10:45:57 GMT</pubDate>
    <dc:creator>Lucas_K</dc:creator>
    <dc:date>2015-04-24T10:45:57Z</dc:date>
    <item>
      <title>How can I restrict a user to only search a specific set of peers in our Splunk Enterprise environment?</title>
      <link>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129704#M3918</link>
      <description>&lt;P&gt;Can I restrict a user to search on a specific set of peers? e.g there are 3 search peers in our splunk enterprise environment, so how can I restrict a user to search by default on only 2 peers and exclude the third one? I know this sort of restriction can be done on an index (internal vs non-internal). &lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Vineet&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2015 15:02:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129704#M3918</guid>
      <dc:creator>vsingla1</dc:creator>
      <dc:date>2015-04-07T15:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: How can I restrict a user to only search a specific set of peers in our Splunk Enterprise environment?</title>
      <link>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129705#M3919</link>
      <description>&lt;P&gt;Can I ask why? That might make your need more clear.&lt;BR /&gt;
When you say "search" do you mean ad_hoc searches? All searches? Are all the indexes the same on all three?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2015 02:43:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129705#M3919</guid>
      <dc:creator>rsennett_splunk</dc:creator>
      <dc:date>2015-04-08T02:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: How can I restrict a user to only search a specific set of peers in our Splunk Enterprise environment?</title>
      <link>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129706#M3920</link>
      <description>&lt;P&gt;This might be helpful to you in the meantime: &lt;A href="http://answers.splunk.com/answers/215164/how-do-i-restrict-searches-to-specific-search-peer.html#answer-227115"&gt;http://answers.splunk.com/answers/215164/how-do-i-restrict-searches-to-specific-search-peer.html#answer-227115&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2015 03:02:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129706#M3920</guid>
      <dc:creator>rsennett_splunk</dc:creator>
      <dc:date>2015-04-08T03:02:28Z</dc:date>
    </item>
    <item>
      <title>Re: How can I restrict a user to only search a specific set of peers in our Splunk Enterprise environment?</title>
      <link>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129707#M3921</link>
      <description>&lt;P&gt;I read it in the Splunk Search manual for 6.1.4. Below is the exact line copied from the manual:&lt;BR /&gt;
"The default peers that you can access are controlled by the roles and permissions associated with your profile and set by your Splunk admin. For more information, see "About users and roles" in Securing Splunk".&lt;/P&gt;

&lt;P&gt;I know it can be specified in the search like splunk_server=. But the manual says it can be controlled via roles and permissions also. That lead to my curosity.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Vineet&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2015 13:31:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129707#M3921</guid>
      <dc:creator>vsingla1</dc:creator>
      <dc:date>2015-04-08T13:31:50Z</dc:date>
    </item>
    <item>
      <title>Re: How can I restrict a user to only search a specific set of peers in our Splunk Enterprise environment?</title>
      <link>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129708#M3922</link>
      <description>&lt;P&gt;Suppose there are three roles - Role1,Role2,Role3. The link that you provided explains that all roles can be restricted to a specific search peer.&lt;BR /&gt;
But is it possible to customize and restrict Role1 to Peer1. Role2 to Peer2 and Role3 to Peer1.&lt;BR /&gt;
I know it can be done for index like Role1 to Index2 and Role2 to Index3 and Role3 to Index1.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2015 16:50:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129708#M3922</guid>
      <dc:creator>vsingla1</dc:creator>
      <dc:date>2015-04-09T16:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: How can I restrict a user to only search a specific set of peers in our Splunk Enterprise environment?</title>
      <link>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129709#M3923</link>
      <description>&lt;P&gt;No, the link to the other answer does not mention "roles". You're right. You can assign specific default indexes to roles, you cannot define specific search peers per role.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2015 16:56:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129709#M3923</guid>
      <dc:creator>rsennett_splunk</dc:creator>
      <dc:date>2015-04-09T16:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: How can I restrict a user to only search a specific set of peers in our Splunk Enterprise environment?</title>
      <link>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129710#M3924</link>
      <description>&lt;P&gt;As I said earlier, from the manual, it seemed this kind of setting could be accomplished. So I thought of exploring more on it. But it seems the search came to a dead end.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2015 17:17:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129710#M3924</guid>
      <dc:creator>vsingla1</dc:creator>
      <dc:date>2015-04-09T17:17:48Z</dc:date>
    </item>
    <item>
      <title>Re: How can I restrict a user to only search a specific set of peers in our Splunk Enterprise environment?</title>
      <link>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129711#M3925</link>
      <description>&lt;P&gt;Yes! You can. So let's make a role, call it TwoPeer. TwoPeer is created in the web interface and has a special setting called "Search Filter". In this box, place the search that will be appended to all searches that are assigned this role. So "splunk_server=sp1 OR splunk_server=sp2" would restrict to those two indexers. Search Filter of "NOT splunk_server=sp3" would give you almost the same result, but would allow the user to search "sp4" if one ever came on line. &lt;/P&gt;

&lt;P&gt;You can also set srchFilter on the authorize.conf file where the roles are defined. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;http://docs.splunk.com/Documentation/Splunk/6.2.2/Admin/Authorizeconf
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:30:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129711#M3925</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2020-09-28T19:30:07Z</dc:date>
    </item>
    <item>
      <title>Re: How can I restrict a user to only search a specific set of peers in our Splunk Enterprise environment?</title>
      <link>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129712#M3926</link>
      <description>&lt;P&gt;I got it. thats very much doable. thanks for the reply.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2015 16:14:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129712#M3926</guid>
      <dc:creator>vsingla1</dc:creator>
      <dc:date>2015-04-10T16:14:25Z</dc:date>
    </item>
    <item>
      <title>Re: How can I restrict a user to only search a specific set of peers in our Splunk Enterprise environment?</title>
      <link>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129713#M3927</link>
      <description>&lt;P&gt;please mark the answer as accepted if it has successfully answered your question. Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2015 16:15:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129713#M3927</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2015-04-10T16:15:58Z</dc:date>
    </item>
    <item>
      <title>Re: How can I restrict a user to only search a specific set of peers in our Splunk Enterprise environment?</title>
      <link>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129714#M3928</link>
      <description>&lt;P&gt;Done!!!!!!&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2015 16:20:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129714#M3928</guid>
      <dc:creator>vsingla1</dc:creator>
      <dc:date>2015-04-10T16:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: How can I restrict a user to only search a specific set of peers in our Splunk Enterprise environment?</title>
      <link>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129715#M3929</link>
      <description>&lt;P&gt;It should be noted that there is a bug (well I think its a bug) with using search filters and roles.&lt;/P&gt;

&lt;P&gt;It has a weird behavior unlike any other setting in splunk.&lt;/P&gt;

&lt;P&gt;If you use any sort of imported role which has search filter, it will NOT be applied IF your current role doesn't explicitly state a search filter option, If you DO include it then it will &lt;STRONG&gt;stack&lt;/STRONG&gt; the filters together and not apply the highest level precedence stanza (ie. the normal operation for every single other stanza in splunk).&lt;/P&gt;

&lt;P&gt;ie. a broken configuration :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;role_user 
 srchFilter = splunk_server=server_1

role_custom_user 
import_role = user
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I found this issue when trying to apply a filter to roles all of which inherited admin/power or user roles.&lt;BR /&gt;
You have to explicitly give every role a filter unfortunately which makes inheritence useless. I had to manually add the filter for 300+ roles &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2015 10:45:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-can-I-restrict-a-user-to-only-search-a-specific-set-of-peers/m-p/129715#M3929</guid>
      <dc:creator>Lucas_K</dc:creator>
      <dc:date>2015-04-24T10:45:57Z</dc:date>
    </item>
  </channel>
</rss>

