<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why are my role-based search filters are not being applied? in Security</title>
    <link>https://community.splunk.com/t5/Security/Why-are-my-role-based-search-filters-are-not-being-applied/m-p/223913#M6343</link>
    <description>&lt;P&gt;I created a role to manage data access for users in a certain LDAP group called role-user.&lt;BR /&gt;
This role has a search filter: &lt;BR /&gt;
I then created a new user account called, role-user-test, in order to verify that this role works correctly.&lt;BR /&gt;
I made sure that the search filter had been applied is visible to the user by doing the search specified &lt;A href="https://answers.splunk.com/answers/79628/debugging-filter-strings-used-with-role-based-access.html#answer-118382"&gt;here.&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;+----------------+--------+-------------------------------+ 
| title          | roles        | search filter           |
+----------------+--------+-------------------------------+ 
| role-user-test |role-user; user | "| search Location=SAX_*" |
+----------------+--------+-------------------------------+ 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However, when I logged in as that user and tried searches, it doesn't seem to be applying the search filter to the user's query at all!&lt;BR /&gt;
The results I see in searches, reports and dashboards still contain results that should have been filtered out.&lt;BR /&gt;
I also tried specifying the search filter different ways, e.g. "Location=SAX_"&lt;BR /&gt;
Are there other configurations for using search filters that I could be missing?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Jan 2016 20:08:58 GMT</pubDate>
    <dc:creator>chustar</dc:creator>
    <dc:date>2016-01-12T20:08:58Z</dc:date>
    <item>
      <title>Why are my role-based search filters are not being applied?</title>
      <link>https://community.splunk.com/t5/Security/Why-are-my-role-based-search-filters-are-not-being-applied/m-p/223913#M6343</link>
      <description>&lt;P&gt;I created a role to manage data access for users in a certain LDAP group called role-user.&lt;BR /&gt;
This role has a search filter: &lt;BR /&gt;
I then created a new user account called, role-user-test, in order to verify that this role works correctly.&lt;BR /&gt;
I made sure that the search filter had been applied is visible to the user by doing the search specified &lt;A href="https://answers.splunk.com/answers/79628/debugging-filter-strings-used-with-role-based-access.html#answer-118382"&gt;here.&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;+----------------+--------+-------------------------------+ 
| title          | roles        | search filter           |
+----------------+--------+-------------------------------+ 
| role-user-test |role-user; user | "| search Location=SAX_*" |
+----------------+--------+-------------------------------+ 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However, when I logged in as that user and tried searches, it doesn't seem to be applying the search filter to the user's query at all!&lt;BR /&gt;
The results I see in searches, reports and dashboards still contain results that should have been filtered out.&lt;BR /&gt;
I also tried specifying the search filter different ways, e.g. "Location=SAX_"&lt;BR /&gt;
Are there other configurations for using search filters that I could be missing?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2016 20:08:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-are-my-role-based-search-filters-are-not-being-applied/m-p/223913#M6343</guid>
      <dc:creator>chustar</dc:creator>
      <dc:date>2016-01-12T20:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: Why are my role-based search filters are not being applied?</title>
      <link>https://community.splunk.com/t5/Security/Why-are-my-role-based-search-filters-are-not-being-applied/m-p/223914#M6344</link>
      <description>&lt;P&gt;Can you just try putting in only the search terms ie&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Location="SAX_*"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Once you run the search check the job inspector to see what's the final search Splunk executed (normalizedSearch OR remoteSearch)&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2016 02:34:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-are-my-role-based-search-filters-are-not-being-applied/m-p/223914#M6344</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2016-01-13T02:34:48Z</dc:date>
    </item>
  </channel>
</rss>

