<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hide scheduled search from indexer in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Hide-scheduled-search-from-indexer/m-p/543788#M5279</link>
    <description>&lt;P&gt;Hello Guys,&lt;/P&gt;&lt;P&gt;we would like to do a group project/contest where different SHs are connected to a IDX-Cluster.&lt;/P&gt;&lt;P&gt;Each SH is for one contestant and the should solve severall search-tasks on the indexed data.&lt;/P&gt;&lt;P&gt;Is there a possibility to "hide" the searches from the indexed data at the indexer cluster or any other splunk-server? So that the contestants could not cheat, if the can look into the _internal index?&lt;/P&gt;&lt;P&gt;I know, that we could restrict the access to the _internal, but let us assume all of them have admin-rights AND access to the shell of the underlying OS?&lt;/P&gt;&lt;P&gt;My guess, it is not possible to hide such a search from the rest of the splunk servers (except the executing SH), because the IDX had to search the data itself.&amp;nbsp;Even not forwarding the internal data to the indexer does not help here. Am I right?&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;BR, Tom&lt;/P&gt;</description>
    <pubDate>Mon, 15 Mar 2021 07:44:58 GMT</pubDate>
    <dc:creator>sscholz</dc:creator>
    <dc:date>2021-03-15T07:44:58Z</dc:date>
    <item>
      <title>Hide scheduled search from indexer</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Hide-scheduled-search-from-indexer/m-p/543788#M5279</link>
      <description>&lt;P&gt;Hello Guys,&lt;/P&gt;&lt;P&gt;we would like to do a group project/contest where different SHs are connected to a IDX-Cluster.&lt;/P&gt;&lt;P&gt;Each SH is for one contestant and the should solve severall search-tasks on the indexed data.&lt;/P&gt;&lt;P&gt;Is there a possibility to "hide" the searches from the indexed data at the indexer cluster or any other splunk-server? So that the contestants could not cheat, if the can look into the _internal index?&lt;/P&gt;&lt;P&gt;I know, that we could restrict the access to the _internal, but let us assume all of them have admin-rights AND access to the shell of the underlying OS?&lt;/P&gt;&lt;P&gt;My guess, it is not possible to hide such a search from the rest of the splunk servers (except the executing SH), because the IDX had to search the data itself.&amp;nbsp;Even not forwarding the internal data to the indexer does not help here. Am I right?&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;BR, Tom&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 07:44:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Hide-scheduled-search-from-indexer/m-p/543788#M5279</guid>
      <dc:creator>sscholz</dc:creator>
      <dc:date>2021-03-15T07:44:58Z</dc:date>
    </item>
  </channel>
</rss>

