<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restrict index access using Eventtype in Security</title>
    <link>https://community.splunk.com/t5/Security/Restrict-index-access-using-Eventtype/m-p/374883#M9253</link>
    <description>&lt;P&gt;You could do that with the "Restrict Search terms" field within a role:&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3142i51AF8316D67149B5/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 30 Jun 2017 02:07:49 GMT</pubDate>
    <dc:creator>kmorris_splunk</dc:creator>
    <dc:date>2017-06-30T02:07:49Z</dc:date>
    <item>
      <title>Restrict index access using Eventtype</title>
      <link>https://community.splunk.com/t5/Security/Restrict-index-access-using-Eventtype/m-p/374881#M9251</link>
      <description>&lt;P&gt;We have over 1000 users, we are using Active Directory, Mapping groups to Roles, and we have 100's of indexes. We need to restrict access to indexes due to sensitive data. Our plan is to use "roles" and restrict the role by Event types. Those Event Types will map to certain indexes using wildcards. The question is: a) is there a better way and b) will this negatively impact performance.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2017 21:25:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Restrict-index-access-using-Eventtype/m-p/374881#M9251</guid>
      <dc:creator>santiagn</dc:creator>
      <dc:date>2017-06-29T21:25:36Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict index access using Eventtype</title>
      <link>https://community.splunk.com/t5/Security/Restrict-index-access-using-Eventtype/m-p/374882#M9252</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;Our plan is to use "roles" and restrict the role by Event types.&lt;BR /&gt;
How do you do that?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;Eventtypes were designed for categorization - so it might be a good choice ; -) &lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2017 00:52:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Restrict-index-access-using-Eventtype/m-p/374882#M9252</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-06-30T00:52:24Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict index access using Eventtype</title>
      <link>https://community.splunk.com/t5/Security/Restrict-index-access-using-Eventtype/m-p/374883#M9253</link>
      <description>&lt;P&gt;You could do that with the "Restrict Search terms" field within a role:&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3142i51AF8316D67149B5/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2017 02:07:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Restrict-index-access-using-Eventtype/m-p/374883#M9253</guid>
      <dc:creator>kmorris_splunk</dc:creator>
      <dc:date>2017-06-30T02:07:49Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict index access using Eventtype</title>
      <link>https://community.splunk.com/t5/Security/Restrict-index-access-using-Eventtype/m-p/374884#M9254</link>
      <description>&lt;P&gt;will this affect performance at all? slower searches etc?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 14:17:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Restrict-index-access-using-Eventtype/m-p/374884#M9254</guid>
      <dc:creator>santiagn</dc:creator>
      <dc:date>2017-07-05T14:17:02Z</dc:date>
    </item>
  </channel>
</rss>

