<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remove search ability users in Security</title>
    <link>https://community.splunk.com/t5/Security/Remove-search-ability-users/m-p/323465#M8336</link>
    <description>&lt;P&gt;oops, my mistake. when i read the question, this issue came to my mind, but then missed it. &lt;/P&gt;

&lt;P&gt;please check this Capability &lt;BR /&gt;
"search" --- Run searches.&lt;/P&gt;

&lt;P&gt;but still, we can add or remove the search capability, but there is no separate capability for granting the dashboard. i think its not possible. lets wait for others answers. &lt;/P&gt;</description>
    <pubDate>Mon, 24 Jul 2017 09:35:19 GMT</pubDate>
    <dc:creator>inventsekar</dc:creator>
    <dc:date>2017-07-24T09:35:19Z</dc:date>
    <item>
      <title>Remove search ability users</title>
      <link>https://community.splunk.com/t5/Security/Remove-search-ability-users/m-p/323462#M8333</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;

&lt;P&gt;I'm trying to set up a monitor/manager account which only has access to dashboards but cannot search through indexes himself.&lt;BR /&gt;
Where do you set this permission? &lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2017 08:42:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Remove-search-ability-users/m-p/323462#M8333</guid>
      <dc:creator>mmoermans</dc:creator>
      <dc:date>2017-07-24T08:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: Remove search ability users</title>
      <link>https://community.splunk.com/t5/Security/Remove-search-ability-users/m-p/323463#M8334</link>
      <description>&lt;P&gt;edit -  not sure if this can be done.. lets wait for others answers. &lt;/P&gt;

&lt;P&gt;not sure of this one, but please check this Capability &lt;BR /&gt;
"search" --- Run searches, &lt;BR /&gt;
"srchIndexesAllowed"&lt;/P&gt;

&lt;P&gt;but still, we can add or remove the search capability, but there is no separate capability for granting the dashboard. i think its not possible. lets wait for others answers. &lt;/P&gt;

&lt;P&gt;"search" --- Run searches, &lt;BR /&gt;
"srchIndexesAllowed" -  User is allowed to search indexes.&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/6.6.2/Security/Rolesandcapabilities"&gt;https://docs.splunk.com/Documentation/Splunk/6.6.2/Security/Rolesandcapabilities&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2017 09:09:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Remove-search-ability-users/m-p/323463#M8334</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2017-07-24T09:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: Remove search ability users</title>
      <link>https://community.splunk.com/t5/Security/Remove-search-ability-users/m-p/323464#M8335</link>
      <description>&lt;P&gt;srchIndexesAllowed only lets you definine which indexes can be searched.&lt;BR /&gt;
If srchIndexesAllowed is empty then no results are found by Monitor user (in dashboards too).&lt;/P&gt;

&lt;P&gt;[role_monitor]&lt;BR /&gt;
cumulativeRTSrchJobsQuota = 0&lt;BR /&gt;
cumulativeSrchJobsQuota = 0&lt;BR /&gt;
importRoles = user_no_index&lt;BR /&gt;
srchIndexesAllowed = network&lt;BR /&gt;
srchIndexesDefault = network&lt;BR /&gt;
srchMaxTime = 0&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:00:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Remove-search-ability-users/m-p/323464#M8335</guid>
      <dc:creator>mmoermans</dc:creator>
      <dc:date>2020-09-29T15:00:41Z</dc:date>
    </item>
    <item>
      <title>Re: Remove search ability users</title>
      <link>https://community.splunk.com/t5/Security/Remove-search-ability-users/m-p/323465#M8336</link>
      <description>&lt;P&gt;oops, my mistake. when i read the question, this issue came to my mind, but then missed it. &lt;/P&gt;

&lt;P&gt;please check this Capability &lt;BR /&gt;
"search" --- Run searches.&lt;/P&gt;

&lt;P&gt;but still, we can add or remove the search capability, but there is no separate capability for granting the dashboard. i think its not possible. lets wait for others answers. &lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2017 09:35:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Remove-search-ability-users/m-p/323465#M8336</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2017-07-24T09:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: Remove search ability users</title>
      <link>https://community.splunk.com/t5/Security/Remove-search-ability-users/m-p/323466#M8337</link>
      <description>&lt;P&gt;After creating user, create a role for this user and assign this role only the read permission for dashboard.&lt;/P&gt;

&lt;P&gt;Please, create a role for this user before create this user, thus you can assign this role for this user and assign only the read permission for this user role.&lt;/P&gt;

&lt;P&gt;if you don't want that user cannot search, either:&lt;/P&gt;

&lt;P&gt;under Indexes, don't select no index, leave input Selected search indexes blank and save. Thus, your user cannot run search.&lt;/P&gt;

&lt;P&gt;create an app for this dashboard and in the default nav four your app, only call the dashboards which user will see like this for example:&lt;/P&gt;

&lt;P&gt;After do this edit your user and give it this app context by default&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/224735/how-to-restrict-a-users-role-to-only-view-a-dashbo.html"&gt;https://answers.splunk.com/answers/224735/how-to-restrict-a-users-role-to-only-view-a-dashbo.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2017 09:49:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Remove-search-ability-users/m-p/323466#M8337</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2017-07-24T09:49:40Z</dc:date>
    </item>
  </channel>
</rss>

