<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ITSI_summary_metrics in roles search restriction in Splunk ITSI</title>
    <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-summary-metrics-in-roles-search-restriction/m-p/554590#M2327</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are developing a query to restrict specific user role to limited services. So we create a query for restriction and we are able to add itsi_summary with serviceid but not sure how to do it for itsi_summary_metrics index. Without metrics index , users are not able see the services assigned to them through teams&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know how write a query for itsi_summary_metrics with serviceid&lt;/P&gt;</description>
    <pubDate>Sat, 05 Jun 2021 11:52:15 GMT</pubDate>
    <dc:creator>Martinnepoleanx</dc:creator>
    <dc:date>2021-06-05T11:52:15Z</dc:date>
    <item>
      <title>ITSI_summary_metrics in roles search restriction</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-summary-metrics-in-roles-search-restriction/m-p/554590#M2327</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are developing a query to restrict specific user role to limited services. So we create a query for restriction and we are able to add itsi_summary with serviceid but not sure how to do it for itsi_summary_metrics index. Without metrics index , users are not able see the services assigned to them through teams&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know how write a query for itsi_summary_metrics with serviceid&lt;/P&gt;</description>
      <pubDate>Sat, 05 Jun 2021 11:52:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/ITSI-summary-metrics-in-roles-search-restriction/m-p/554590#M2327</guid>
      <dc:creator>Martinnepoleanx</dc:creator>
      <dc:date>2021-06-05T11:52:15Z</dc:date>
    </item>
    <item>
      <title>Re: ITSI_summary_metrics in roles search restriction</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-summary-metrics-in-roles-search-restriction/m-p/565856#M2405</link>
      <description>&lt;P&gt;The itsi_summary_metrics index is a &lt;STRONG&gt;metric&lt;/STRONG&gt; format&lt;BR /&gt;You probably cannot use the same logic that for an "&lt;STRONG&gt;event&lt;/STRONG&gt; format" index.&lt;BR /&gt;I do not know if this possible to do a filter that works for metric, or for metric AND events.&lt;BR /&gt;&lt;BR /&gt;The docs are not clear on that, they only give SPL filters examples :&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.2/Security/Addandeditroles#Specify_search_restrictions_for_a_role" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.2/Security/Addandeditroles#Specify_search_restrictions_for_a_role&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;To test :&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;create a test user and test role&lt;/LI&gt;&lt;LI&gt;add a filter to the role&lt;/LI&gt;&lt;LI&gt;run a search as that user, and open the search inspector, you will see the "extended search" query, and see how the filter was added automatically, see if you can figure it out&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Fri, 03 Sep 2021 19:53:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/ITSI-summary-metrics-in-roles-search-restriction/m-p/565856#M2405</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2021-09-03T19:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: ITSI_summary_metrics in roles search restriction</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/ITSI-summary-metrics-in-roles-search-restriction/m-p/565858#M2407</link>
      <description>&lt;P&gt;Are you trying to restrict access to the service view, or the underlying data the search returns?&amp;nbsp; Metrics have no real private info except a host name so not really sure why you are restricting this way.&amp;nbsp; Use teams instead from within ITSI to assign which services which members can see.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 20:04:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/ITSI-summary-metrics-in-roles-search-restriction/m-p/565858#M2407</guid>
      <dc:creator>eduncan</dc:creator>
      <dc:date>2021-09-03T20:04:24Z</dc:date>
    </item>
  </channel>
</rss>

