<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Experiencing role/index/restriction problem in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Experiencing-role-index-restriction-problem/m-p/596243#M8797</link>
    <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;this was my fear after i read the comment of richgalloway.&lt;BR /&gt;that's completely stupid, but it's like it is.&lt;BR /&gt;i'm fiddling already around with reindexing the files to a new index, but for some reason splunk will not do so &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;there seems to be no way to make splunk forget about an already indexed file and reindex the same file to a new index. besides changing the first line of the file. this is not what i want to do.&lt;BR /&gt;maybe i'm going &lt;A href="https://community.splunk.com/t5/Knowledge-Management/HOW-TO-Purge-CLEAN-Selective-Data-from-an-Index/m-p/434513" target="_blank" rel="noopener"&gt;this&lt;/A&gt;&amp;nbsp;way&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;thanks for bringing light in the dark &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 03 May 2022 11:04:21 GMT</pubDate>
    <dc:creator>pbnl</dc:creator>
    <dc:date>2022-05-03T11:04:21Z</dc:date>
    <item>
      <title>Experiencing role/index/restriction problem</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Experiencing-role-index-restriction-problem/m-p/595783#M8785</link>
      <description>&lt;P&gt;hi all,&lt;/P&gt;
&lt;P&gt;i have an app with several dashboards, each displaying data from different indexes.&lt;BR /&gt;the users have roles assigned, which allow them to view different dashboards.&lt;BR /&gt;the roles allow access to different indexes.&lt;BR /&gt;some month ago, i've added a monitor that sends the data to the 'main' index using a datasource. now i'm asked to add a dashboard for this data and allow some users to use it. i've added a role, inherited the company base user role and capabilities, the index 'main' and a restriction to the datasource.&lt;BR /&gt;my testuser that only has this role can use the dashboard. BUT: as soon i add this role to other users, they can use this new dashboard, but not the otherones anymore. they simply say '&lt;SPAN&gt;No results found.'&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;any ideas?&lt;BR /&gt;thanks...&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 18:10:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Experiencing-role-index-restriction-problem/m-p/595783#M8785</guid>
      <dc:creator>pbnl</dc:creator>
      <dc:date>2022-04-28T18:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: role/index/restriction problem</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Experiencing-role-index-restriction-problem/m-p/595787#M8786</link>
      <description>&lt;P&gt;Please tell us more about the "restriction to the datasource".&amp;nbsp; What kind of restriction?&amp;nbsp; It's possible this restriction is affecting access to other sources so the more you can tell us about the better we can help.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 13:41:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Experiencing-role-index-restriction-problem/m-p/595787#M8786</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-04-28T13:41:01Z</dc:date>
    </item>
    <item>
      <title>Re: role/index/restriction problem</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Experiencing-role-index-restriction-problem/m-p/595792#M8787</link>
      <description>&lt;P&gt;the restriction i added when creating the role is:&lt;BR /&gt;sourcetype::log4jscan&lt;/P&gt;&lt;P&gt;when i click on '&lt;SPAN&gt;Preview search filter results' i get:&lt;/SPAN&gt;&lt;BR /&gt;index=main | search sourcetype::log4jscan&lt;/P&gt;&lt;P&gt;this give me the results i want. but running a search from an other role e.g.&lt;BR /&gt;index=msexchange OR index=srv066-vm OR index=srv067-vm OR index=ve2k8clu&lt;BR /&gt;doesn't return any results&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 14:14:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Experiencing-role-index-restriction-problem/m-p/595792#M8787</guid>
      <dc:creator>pbnl</dc:creator>
      <dc:date>2022-04-28T14:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: Experiencing role/index/restriction problem</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Experiencing-role-index-restriction-problem/m-p/596114#M8795</link>
      <description>&lt;P&gt;nobody any idea here?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2022 07:05:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Experiencing-role-index-restriction-problem/m-p/596114#M8795</guid>
      <dc:creator>pbnl</dc:creator>
      <dc:date>2022-05-02T07:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: Experiencing role/index/restriction problem</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Experiencing-role-index-restriction-problem/m-p/596140#M8796</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;When you have added a search filter to any role and then you add that role to anyone else which have some other roles splunk merges those role definitions together. And this means that this search filter is added to all users which have this role. For that reason they cannot see anything else than this search filter allow.&lt;/P&gt;&lt;P&gt;My own suggestion is not to use any search filters as those usually generate more issues than solve! Also I try to avoid to use main/default index for anything. It's much easier to forward this kind of events to own index and then restrict access by index not by any search filter.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2022 11:28:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Experiencing-role-index-restriction-problem/m-p/596140#M8796</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-05-02T11:28:27Z</dc:date>
    </item>
    <item>
      <title>Re: Experiencing role/index/restriction problem</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Experiencing-role-index-restriction-problem/m-p/596243#M8797</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;this was my fear after i read the comment of richgalloway.&lt;BR /&gt;that's completely stupid, but it's like it is.&lt;BR /&gt;i'm fiddling already around with reindexing the files to a new index, but for some reason splunk will not do so &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;there seems to be no way to make splunk forget about an already indexed file and reindex the same file to a new index. besides changing the first line of the file. this is not what i want to do.&lt;BR /&gt;maybe i'm going &lt;A href="https://community.splunk.com/t5/Knowledge-Management/HOW-TO-Purge-CLEAN-Selective-Data-from-an-Index/m-p/434513" target="_blank" rel="noopener"&gt;this&lt;/A&gt;&amp;nbsp;way&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;thanks for bringing light in the dark &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 11:04:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Experiencing-role-index-restriction-problem/m-p/596243#M8797</guid>
      <dc:creator>pbnl</dc:creator>
      <dc:date>2022-05-03T11:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: Experiencing role/index/restriction problem</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Experiencing-role-index-restriction-problem/m-p/596253#M8798</link>
      <description>&lt;P&gt;You can reindexing files by clearing fish bucket information on source system. See more&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/CommandlinetoolsforusewithSupport" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/CommandlinetoolsforusewithSupport&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://community.splunk.com/t5/Deployment-Architecture/Use-btprobe-reset-to-re-index-multiple-files/m-p/313186" target="_blank"&gt;https://community.splunk.com/t5/Deployment-Architecture/Use-btprobe-reset-to-re-index-multiple-files/m-p/313186&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/btprobe-and-re-indexing-data/m-p/108265" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/btprobe-and-re-indexing-data/m-p/108265&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Definitely you can find a lot more instructions how to do it if needed.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 13:35:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Experiencing-role-index-restriction-problem/m-p/596253#M8798</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-05-03T13:35:52Z</dc:date>
    </item>
  </channel>
</rss>

