<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there a way to restrict Splunk admin access to search for index=*? in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Is-there-a-way-to-restrict-Splunk-admin-access-to-search-for/m-p/644233#M9478</link>
    <description>&lt;P&gt;I tried creating a Admission rule for the condition "&lt;SPAN&gt;index=* OR search_time_range=alltime"&amp;nbsp;&lt;/SPAN&gt;but looks like the setting is not getting applied. Users are still able to search for index=*. Does this work on Clustered environment or is there any additional steps I need to follow for cluster env?&amp;nbsp; We have SH cluster.&lt;/P&gt;</description>
    <pubDate>Tue, 23 May 2023 09:08:30 GMT</pubDate>
    <dc:creator>Navanitha</dc:creator>
    <dc:date>2023-05-23T09:08:30Z</dc:date>
    <item>
      <title>Is there a way to restrict Splunk admin access to search for index=*?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Is-there-a-way-to-restrict-Splunk-admin-access-to-search-for/m-p/644164#M9476</link>
      <description>&lt;P&gt;How to restrict access for a Splunk admin role from being able to run index="*" search.&amp;nbsp; This is killing our Splunk resources and need to restrict the access.&amp;nbsp; Apart from User awareness / Education, is there any way to implement this ?&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2023 17:58:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Is-there-a-way-to-restrict-Splunk-admin-access-to-search-for/m-p/644164#M9476</guid>
      <dc:creator>Navanitha</dc:creator>
      <dc:date>2023-05-22T17:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to restrict Splunk admin access to search for index=*?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Is-there-a-way-to-restrict-Splunk-admin-access-to-search-for/m-p/644169#M9477</link>
      <description>&lt;P&gt;Use the Admission Rules feature of Workload Management.&amp;nbsp; Go to Settings-&amp;gt;Workload management.&amp;nbsp; See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.4/Workloads/AdmissionRules" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.4/Workloads/AdmissionRules&lt;/A&gt;&amp;nbsp;for details.&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2023 18:48:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Is-there-a-way-to-restrict-Splunk-admin-access-to-search-for/m-p/644169#M9477</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-05-22T18:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to restrict Splunk admin access to search for index=*?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Is-there-a-way-to-restrict-Splunk-admin-access-to-search-for/m-p/644233#M9478</link>
      <description>&lt;P&gt;I tried creating a Admission rule for the condition "&lt;SPAN&gt;index=* OR search_time_range=alltime"&amp;nbsp;&lt;/SPAN&gt;but looks like the setting is not getting applied. Users are still able to search for index=*. Does this work on Clustered environment or is there any additional steps I need to follow for cluster env?&amp;nbsp; We have SH cluster.&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 09:08:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Is-there-a-way-to-restrict-Splunk-admin-access-to-search-for/m-p/644233#M9478</guid>
      <dc:creator>Navanitha</dc:creator>
      <dc:date>2023-05-23T09:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to restrict Splunk admin access to search for index=*?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Is-there-a-way-to-restrict-Splunk-admin-access-to-search-for/m-p/644279#M9479</link>
      <description>&lt;P&gt;Yes, Admission Rules should work on a SHC.&amp;nbsp; It make take a short time for the changes to propagate to the rest of the cluster, but it should work.&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 16:08:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Is-there-a-way-to-restrict-Splunk-admin-access-to-search-for/m-p/644279#M9479</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-05-23T16:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to restrict Splunk admin access to search for index=*?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Is-there-a-way-to-restrict-Splunk-admin-access-to-search-for/m-p/644304#M9480</link>
      <description>&lt;P&gt;It is not working.&amp;nbsp; I did add/update&amp;nbsp;&lt;SPAN&gt;workload_rules.conf on all our Splunk SH's in our cluster still no luck.&amp;nbsp; Does it need any Splunk restart or do I have to assign it to users / roles just thinking loud.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This is what I have in workload_rules.conf under&amp;nbsp;/opt/splunk/etc/apps/search/local&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[search_filter_rule:WildcardSearch]&lt;BR /&gt;action = filter&lt;BR /&gt;predicate = index=* OR search_time_range=alltime&lt;BR /&gt;user_message = Please provide index name&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 17:50:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Is-there-a-way-to-restrict-Splunk-admin-access-to-search-for/m-p/644304#M9480</guid>
      <dc:creator>Navanitha</dc:creator>
      <dc:date>2023-05-23T17:50:42Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to restrict Splunk admin access to search for index=*?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Is-there-a-way-to-restrict-Splunk-admin-access-to-search-for/m-p/644338#M9481</link>
      <description>&lt;P&gt;There's no need for a restart if you set up the Admission Rule using the GUI.&amp;nbsp; If you edit the config file then a restart is necessary.&amp;nbsp; The rule will apply to all users/roles unless the predicate says otherwise.&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 18:46:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Is-there-a-way-to-restrict-Splunk-admin-access-to-search-for/m-p/644338#M9481</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-05-23T18:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to restrict Splunk admin access to search for index=*?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Is-there-a-way-to-restrict-Splunk-admin-access-to-search-for/m-p/644451#M9484</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;stupid question, but have you enabled Admission Rules? This must do by that activation switch which said "Admission Rules Disabled". Click it and then you have here the text "Admission Rules Enabled". To be honest this is not a best way to told that this is not in use &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 09:55:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Is-there-a-way-to-restrict-Splunk-admin-access-to-search-for/m-p/644451#M9484</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-05-24T09:55:44Z</dc:date>
    </item>
  </channel>
</rss>

