<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk enterprise configuration in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/557383#M5099</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235615"&gt;@adminp4l&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;at first check the enabled indexes for each roles: you have to give to each solo, only the access to the requested indexes.&lt;/P&gt;&lt;P&gt;Then you have to check if there's some "&lt;SPAN&gt;Inheritance", because in this case, the role takes the grantes of the inheritated role.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Jun 2021 09:15:09 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2021-06-28T09:15:09Z</dc:date>
    <item>
      <title>Splunk enterprise configuration</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/556451#M5080</link>
      <description>&lt;DIV&gt;&lt;DIV&gt;Hi,&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;We are planing to go for Splunk Enterprise. Could you please clarify my below queries to make us more understandable.&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;1. Can we use multiple projects in one login itself.&lt;BR /&gt;2. How can we search individual projects in Splunk, means each project owner have only access or visible to their particular projects.&lt;BR /&gt;3. Is all logging happened in the server where we hosted our applications.&lt;BR /&gt;4. Duration for maintaining all logs. Are we get logs for last 1 year. I can see up to 30 days in the filter option.&lt;BR /&gt;5. Cost for the subscription which includes support.&lt;/DIV&gt;&lt;DIV&gt;6. How about the renewal options.&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 21 Jun 2021 04:23:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/556451#M5080</guid>
      <dc:creator>adminp4l</dc:creator>
      <dc:date>2021-06-21T04:23:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise configuration</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/556470#M5081</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235615"&gt;@adminp4l&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I try to answer to your questions:&lt;/P&gt;&lt;DIV&gt;&lt;STRONG&gt;1. Can we use multiple projects in one login itself.&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;If you're speaking of Splunk Could, users of a subscription can access only data and apps of the subscription.&lt;/DIV&gt;&lt;DIV&gt;Then, In Splunk it's possible to define roles (containing also one user) and to give to one role the grants on an App or one or more knowledge objects.&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;So each login can see the Apps shared with his role, and the Search and Reporting App that's common (it's also possible to disable access to this app).&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;P&gt;&lt;STRONG&gt;2. How can we search individual projects in Splunk, means each project owner have only access or visible to their particular projects.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What do you mean with "Projects"?&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;If you mean an App, e&lt;SPAN&gt;ach user can build his apps and define the share rules:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;Open to all: sharing with "Everyone" apps and knowledge objects,&lt;/LI&gt;&lt;LI&gt;Open to App: sharing objects at app level and defining the roles that can access an app,&lt;/LI&gt;&lt;LI&gt;Private: each user can see only his apps and knowledge objects.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;3. Is all logging happened in the server where we hosted our applications.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Splunk logs every action on the system in the _audit and _internal indexes.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;4. Duration for maintaining all logs. Are we get logs for last 1 year. I can see up to 30 days in the filter option.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If you're speaking of Splunk on premise, you can define the retention of your logs by yourself, but remember that you have to do a Capacity Plan to define the storage requirements for a retention of one year.&lt;/P&gt;&lt;P&gt;If instead you're speaking of Splunk Cloud, the default retention is 90 days but you can buy a longer retention.&lt;/P&gt;&lt;P&gt;About filters, for my knowledge, it isn't possible to limit the filtering period, but you can delete the default filter options greater than 30 days, but this doesn't limity the possibility to manually set a greater search period.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;5. Cost for the subscription which includes support.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Abut costs, they depends on the volume of your logs: you pay a license for the daily indexed logs.&lt;/P&gt;&lt;P&gt;You have to define your usual logs volume and buy a license for them, you can exceed this value for 45 times in the last 60 days, so you have to make a puntual Capacity Plan for your license.&lt;/P&gt;&lt;P&gt;For the cost, you have to ask to your Splunk partner that asks to the local distributor.&lt;/P&gt;&lt;P&gt;Here you can find more infos:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.splunk.com/en_us/software/pricing.html?utm_campaign=google_emea_tier2_en_search_brand" target="_blank" rel="noopener"&gt;https://www.splunk.com/en_us/software/pricing.html?utm_campaign=google_emea_tier2_en_search_brand&lt;/A&gt;&lt;/P&gt;&lt;P&gt;In Internet there is also this site, but I'm not sure that's a Splunk official site&amp;nbsp;&lt;A href="https://splunkpricing.com/" target="_blank" rel="noopener"&gt;https://splunkpricing.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Some months ago there was an official Splunk prices page, but now there isn't more.&lt;/P&gt;&lt;DIV&gt;&lt;STRONG&gt;6. How about the renewal options.&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;You can renew your subscription when it's finishing, contacting the Partner that sold you the original subscription.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Ciao.&lt;/DIV&gt;&lt;DIV&gt;Giuseppe&lt;/DIV&gt;</description>
      <pubDate>Mon, 21 Jun 2021 06:09:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/556470#M5081</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-06-21T06:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise configuration</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/556514#M5082</link>
      <description>&lt;P&gt;It would be helpful if u provide a tutorial about this topic for Splunk Enterprise&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 12:34:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/556514#M5082</guid>
      <dc:creator>adminp4l</dc:creator>
      <dc:date>2021-06-21T12:34:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise configuration</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/556515#M5083</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235615"&gt;@adminp4l&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;which topic are you speaking of?&lt;/P&gt;&lt;P&gt;You can find a Tutorial for the SQL (the search language of Splunk) at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.0/SearchTutorial/WelcometotheSearchTutorial" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.0/SearchTutorial/WelcometotheSearchTutorial&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You can find free courses about Splunk fundamentals and architecture at&amp;nbsp;&lt;A href="https://www.splunk.com/en_us/training/free-courses/splunk-fundamentals-1.html" target="_blank"&gt;https://www.splunk.com/en_us/training/free-courses/splunk-fundamentals-1.html&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://www.splunk.com/en_us/training/free-courses/splunk-infastructure-overview.html" target="_blank"&gt;https://www.splunk.com/en_us/training/free-courses/splunk-infastructure-overview.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Then you can find many videos on YouTube.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 12:45:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/556515#M5083</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-06-21T12:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise configuration</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/556608#M5087</link>
      <description>&lt;P&gt;Dear G&lt;SPAN&gt;cusello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am using Splunk enterprise and looking for how to configure o&lt;/SPAN&gt;&lt;SPAN&gt;nly respective team members have access to their own projects not other projects.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It would be very much helpful if you could provide any tutorials for creating multiple projects logs with permission to access in one login itself.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 03:40:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/556608#M5087</guid>
      <dc:creator>adminp4l</dc:creator>
      <dc:date>2021-06-22T03:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise configuration</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/556626#M5088</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235615"&gt;@adminp4l&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as you can see at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.0/Admin/Aboutusersandroles," target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.0/Admin/Aboutusersandroles,&lt;/A&gt;&amp;nbsp;the steps to configure access grants to apps is something like this (with only local users):&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;create a role for each group of users with the access rights [Settings -- Roles -- New Role],&lt;/LI&gt;&lt;LI&gt;don't use "Inheritance" in role creation, but assign only the needed functions and indexes,&lt;/LI&gt;&lt;LI&gt;assign each user to one or more roles [Settings -- Users]&lt;/LI&gt;&lt;LI&gt;assign to each App only the roles for that App [Apps -- Manage Apps --- Permissions].&lt;/LI&gt;&lt;LI&gt;assign to each Knowledge Objects of each App only the roles for that App [Permissions].&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;In this way you're sure that each user can access only the neede Apps, Functions and Indexes.&lt;/P&gt;&lt;P&gt;Probably this video will help you&amp;nbsp;&lt;A href="https://www.youtube.com/watch?v=A4IRcdSKmys" target="_blank" rel="noopener"&gt;https://www.youtube.com/watch?v=A4IRcdSKmys&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you use Active Directory or SAML as authentication the procedure is the same for the roles creation and different in User / rolesa association as you can see at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.0/InheritedDeployment/Usersrolesandauthentication" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.0/InheritedDeployment/Usersrolesandauthentication&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 06:49:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/556626#M5088</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-06-22T06:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise configuration</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/556799#M5091</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352" target="_self"&gt;&lt;SPAN class="login-bold"&gt;Gcusello,&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="login-bold"&gt;Thanks for your valuable comments. Let me try to implement according to user specific in my c# code. If any blockages will reach out to you.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="login-bold"&gt;Appreciate your support.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 03:35:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/556799#M5091</guid>
      <dc:creator>adminp4l</dc:creator>
      <dc:date>2021-06-23T03:35:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise configuration</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/556815#M5092</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235615"&gt;@adminp4l&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;let me know if I'll be able to help you&amp;nbsp; next time.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 06:25:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/556815#M5092</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-06-23T06:25:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise configuration</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/557360#M5097</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352" target="_self"&gt;&lt;SPAN class="login-bold"&gt;gcusello,&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="login-bold"&gt;We have created different user roles. But each user can able to view all project logs. Can we restrict these user to view other project logs. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="login-bold"&gt;It would be much appreciate if you can share settings the view permission to restrict for other projects view.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 06:55:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/557360#M5097</guid>
      <dc:creator>adminp4l</dc:creator>
      <dc:date>2021-06-28T06:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise configuration</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/557383#M5099</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235615"&gt;@adminp4l&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;at first check the enabled indexes for each roles: you have to give to each solo, only the access to the requested indexes.&lt;/P&gt;&lt;P&gt;Then you have to check if there's some "&lt;SPAN&gt;Inheritance", because in this case, the role takes the grantes of the inheritated role.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 09:15:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/557383#M5099</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-06-28T09:15:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise configuration</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/557516#M5102</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352" target="_self"&gt;&lt;SPAN class="login-bold"&gt;gcusello&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks for sharing the information, Can we get any video tutorial for the same.&lt;/P&gt;&lt;P&gt;Also we are implementing logs from our C# code. It would be much helpful if you can consider this also.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 05:01:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/557516#M5102</guid>
      <dc:creator>adminp4l</dc:creator>
      <dc:date>2021-06-29T05:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise configuration</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/557753#M5111</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235615"&gt;@adminp4l&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;use Google to search Splunk videos and you'll surely find!&lt;/P&gt;&lt;P&gt;Anyway, for Users and roles see this:&amp;nbsp;&lt;A href="https://www.youtube.com/watch?v=A4IRcdSKmys" target="_blank"&gt;https://www.youtube.com/watch?v=A4IRcdSKmys&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 06:53:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-enterprise-configuration/m-p/557753#M5111</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-06-30T06:53:21Z</dc:date>
    </item>
  </channel>
</rss>

