<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sourcetype restricted access in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-restricted-access/m-p/704489#M116497</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273723"&gt;@splunklearner&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you have to create a Splunk Role for each AD Group.&lt;/P&gt;&lt;P&gt;Then in each role, you have to fix the index to use and/or the additional filtering options.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Fri, 15 Nov 2024 08:54:38 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2024-11-15T08:54:38Z</dc:date>
    <item>
      <title>Sourcetype restricted access</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-restricted-access/m-p/704467#M116490</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;We have specific AD group for specific application and we create index for that app and restrict access to that AD group (for all app users of that specific app) for that specific index. Generally they will be given FQDN/Hostname to us and we will be mapping to the particular index.&lt;/P&gt;&lt;P&gt;In this way we have numerous AD groups and indexes.&lt;/P&gt;&lt;P&gt;But our client is expecting less AD groups because it is difficult to maintain those many AD groups.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, here my question... is there any chance to reduce AD groups by restricting specific to Source type rather than Index? So in one index can we have multiple applications where we can restrict them by sourcetype? If yes, please help me with the approach?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 04:04:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-restricted-access/m-p/704467#M116490</guid>
      <dc:creator>splunklearner</dc:creator>
      <dc:date>2024-11-15T04:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype restricted access</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-restricted-access/m-p/704480#M116493</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273723"&gt;@splunklearner&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;No, the data access is managed in Splunk at index level, but must every AD group see only one ore any indexes?&lt;/P&gt;&lt;P&gt;I suppose that you are trying to manage multitenancy, in this way different indexes is the only solution.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 07:07:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-restricted-access/m-p/704480#M116493</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-11-15T07:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype restricted access</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-restricted-access/m-p/704483#M116494</link>
      <description>&lt;P&gt;For suppose... 'X' application has specific AD group say "Y" and specific index "Z"...&lt;/P&gt;&lt;P&gt;Generally X application team members/owners are in Y group and should access Z index. This is fine till here.&lt;/P&gt;&lt;P&gt;But client concerned about numerous applications having numerous AD groups which will be difficult to maintain.&lt;/P&gt;&lt;P&gt;So for suppose in single AD group can we include multiple app teams with multiple indexes and can we restrict them by sourcetype specifying to that particular app? Is it possible or any other ways to do this? To reduce AD groups at the same time app level restriction should be there.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 07:44:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-restricted-access/m-p/704483#M116494</guid>
      <dc:creator>splunklearner</dc:creator>
      <dc:date>2024-11-15T07:44:29Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype restricted access</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-restricted-access/m-p/704484#M116495</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273723"&gt;@splunklearner&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;as you well know, AD Groups are associated to one or more Splunk Roles and data access is managed associating Roles and indexes.&lt;/P&gt;&lt;P&gt;You eventually can filter access to the data of the same index inserting a filter (e.g. a sourcetype or one other field), in this way, you can reduce the indexes number but anyway, you have to identify a rule to filter data access;&lt;/P&gt;&lt;P&gt;usually sourcetype isn't the best solution because sourcetype is usually associated to the logs&amp;nbsp; or to the technology, if you could identify onother field, you could do it.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 08:04:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-restricted-access/m-p/704484#M116495</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-11-15T08:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype restricted access</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-restricted-access/m-p/704485#M116496</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;How to assign specific index to specific AD group and how to map specific FQDN to that particular index, so that specific AD group should see their logs only?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 08:27:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-restricted-access/m-p/704485#M116496</guid>
      <dc:creator>splunklearner</dc:creator>
      <dc:date>2024-11-15T08:27:40Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype restricted access</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-restricted-access/m-p/704489#M116497</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273723"&gt;@splunklearner&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you have to create a Splunk Role for each AD Group.&lt;/P&gt;&lt;P&gt;Then in each role, you have to fix the index to use and/or the additional filtering options.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 08:54:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-restricted-access/m-p/704489#M116497</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-11-15T08:54:38Z</dc:date>
    </item>
  </channel>
</rss>

