<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restrict REST access to a specific index in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Restrict-REST-access-to-a-specific-index/m-p/101894#M21358</link>
    <description>&lt;P&gt;Yes, this appears to have been the problem.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Thu, 25 Oct 2012 13:58:47 GMT</pubDate>
    <dc:creator>rmorlen</dc:creator>
    <dc:date>2012-10-25T13:58:47Z</dc:date>
    <item>
      <title>Restrict REST access to a specific index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Restrict-REST-access-to-a-specific-index/m-p/101891#M21355</link>
      <description>&lt;P&gt;We have defined a role:&lt;/P&gt;

&lt;P&gt;[role_rest_role]&lt;/P&gt;

&lt;P&gt;importRoles = can_delete;user&lt;/P&gt;

&lt;P&gt;rtSrchJobsQuota = 0&lt;/P&gt;

&lt;P&gt;srchDiskQuota = 0&lt;/P&gt;

&lt;P&gt;srchIndexesAllowed = indexA&lt;/P&gt;

&lt;P&gt;srchIndexesDefault = indexA&lt;/P&gt;

&lt;P&gt;srchJobsQuota = 0&lt;/P&gt;

&lt;P&gt;We have created a local user that has this role.  The problem is that doing a search using REST the user has access to index=main.  Since this user "can_delete" we really want to restrict their access to a specific index.&lt;/P&gt;

&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2012 20:38:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Restrict-REST-access-to-a-specific-index/m-p/101891#M21355</guid>
      <dc:creator>rmorlen</dc:creator>
      <dc:date>2012-10-24T20:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict REST access to a specific index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Restrict-REST-access-to-a-specific-index/m-p/101892#M21356</link>
      <description>&lt;P&gt;It inherits the user role - doesn't this role have access to index main? If so, you need to remove this inheritance.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2012 20:50:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Restrict-REST-access-to-a-specific-index/m-p/101892#M21356</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-10-24T20:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict REST access to a specific index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Restrict-REST-access-to-a-specific-index/m-p/101893#M21357</link>
      <description>&lt;P&gt;I suspected this.  Trying this today.  I will post a response on the results.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2012 13:54:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Restrict-REST-access-to-a-specific-index/m-p/101893#M21357</guid>
      <dc:creator>rmorlen</dc:creator>
      <dc:date>2012-10-25T13:54:19Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict REST access to a specific index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Restrict-REST-access-to-a-specific-index/m-p/101894#M21358</link>
      <description>&lt;P&gt;Yes, this appears to have been the problem.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2012 13:58:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Restrict-REST-access-to-a-specific-index/m-p/101894#M21358</guid>
      <dc:creator>rmorlen</dc:creator>
      <dc:date>2012-10-25T13:58:47Z</dc:date>
    </item>
  </channel>
</rss>

