<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Distributed Search and Roles in Security</title>
    <link>https://community.splunk.com/t5/Security/Distributed-Search-and-Roles/m-p/144867#M4434</link>
    <description>&lt;P&gt;This is correct, and probably the best you can do. Just note that the &lt;EM&gt;administrator&lt;/EM&gt; of the search head can still have access to all indexers data, as the role/index access is controlled and managed on the search head, not on the indexer.&lt;/P&gt;</description>
    <pubDate>Sat, 16 Nov 2013 01:21:37 GMT</pubDate>
    <dc:creator>gkanapathy</dc:creator>
    <dc:date>2013-11-16T01:21:37Z</dc:date>
    <item>
      <title>Distributed Search and Roles</title>
      <link>https://community.splunk.com/t5/Security/Distributed-Search-and-Roles/m-p/144865#M4432</link>
      <description>&lt;P&gt;I have a Search Head with three indexers setup in distributed search.&lt;/P&gt;

&lt;P&gt;There is another team in our enterprise that has logs in there own indexer and out team has access to there search head using AD.&lt;/P&gt;

&lt;P&gt;So that the team dose not have to use two windows to access the data from both sets of indexers I can setup distributed search to all the indexers just using different credentials for my indexers and for the other teams indexer.&lt;/P&gt;

&lt;P&gt;The problem is that not everyone in my environment is allowed to see the logs from the other indexer.  How can the admin of the other instance control access to the people on my search head?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2013 22:02:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Distributed-Search-and-Roles/m-p/144865#M4432</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2013-11-15T22:02:40Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed Search and Roles</title>
      <link>https://community.splunk.com/t5/Security/Distributed-Search-and-Roles/m-p/144866#M4433</link>
      <description>&lt;P&gt;You can configure Roles to have access to specific indexes (assuming other team is using different index names then yours).&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2013 22:16:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Distributed-Search-and-Roles/m-p/144866#M4433</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2013-11-15T22:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed Search and Roles</title>
      <link>https://community.splunk.com/t5/Security/Distributed-Search-and-Roles/m-p/144867#M4434</link>
      <description>&lt;P&gt;This is correct, and probably the best you can do. Just note that the &lt;EM&gt;administrator&lt;/EM&gt; of the search head can still have access to all indexers data, as the role/index access is controlled and managed on the search head, not on the indexer.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Nov 2013 01:21:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Distributed-Search-and-Roles/m-p/144867#M4434</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2013-11-16T01:21:37Z</dc:date>
    </item>
  </channel>
</rss>

