<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restrict Export of Sensitive Data in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Restrict-Export-of-Sensitive-Data/m-p/329276#M5943</link>
    <description>&lt;P&gt;Hi @brreeves, thank you for the confirmation.&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;

&lt;P&gt;Chris&lt;/P&gt;</description>
    <pubDate>Thu, 13 Apr 2017 13:30:03 GMT</pubDate>
    <dc:creator>IRHM73</dc:creator>
    <dc:date>2017-04-13T13:30:03Z</dc:date>
    <item>
      <title>Restrict Export of Sensitive Data</title>
      <link>https://community.splunk.com/t5/Reporting/Restrict-Export-of-Sensitive-Data/m-p/329274#M5941</link>
      <description>&lt;P&gt;Hi, I wonder whether someone could help me please.&lt;/P&gt;

&lt;P&gt;The Splunk environment I administer contains sensitive personal data which only those with the relevant clearance can view.&lt;/P&gt;

&lt;P&gt;To add an extra line of security, my security team have asked me to remove the 'export' function so these personal details can't be downloaded, that is, until the relevant clearance is provided.&lt;/P&gt;

&lt;P&gt;I can make the changes via the 'authorize.conf' file to the user role, setting the 'export_is_visible' in the 'Parent' role to disabled and then a 'child' role which enables the capability.&lt;/P&gt;

&lt;P&gt;The problem I have is:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt; I want to restrict this via app, rather than a 'global ' restriction, because in addition to apps with dashboards containing sensitive data, they have access to apps with dashboards which have pure statistical data.&lt;/LI&gt;
&lt;LI&gt;In addition, I can't change the role associated with the app, because if I change this, everyone who can just view the statistical dashboards and hence can download the data will also be affected.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Could someone tell me please is there another way to achieve this?&lt;/P&gt;

&lt;P&gt;Many thanks and kind regards&lt;/P&gt;

&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:40:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Restrict-Export-of-Sensitive-Data/m-p/329274#M5941</guid>
      <dc:creator>IRHM73</dc:creator>
      <dc:date>2020-09-29T13:40:13Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict Export of Sensitive Data</title>
      <link>https://community.splunk.com/t5/Reporting/Restrict-Export-of-Sensitive-Data/m-p/329275#M5942</link>
      <description>&lt;P&gt;@IRHM73, apps are deployed to machines, not to people. I don't think you'll be able to do what you're trying to do unless you want to give access to a specific machine once clearance is given.&lt;/P&gt;

&lt;P&gt;Global Roles are the best way to achieve this.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2017 13:15:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Restrict-Export-of-Sensitive-Data/m-p/329275#M5942</guid>
      <dc:creator>brreeves_splunk</dc:creator>
      <dc:date>2017-04-13T13:15:12Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict Export of Sensitive Data</title>
      <link>https://community.splunk.com/t5/Reporting/Restrict-Export-of-Sensitive-Data/m-p/329276#M5943</link>
      <description>&lt;P&gt;Hi @brreeves, thank you for the confirmation.&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;

&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2017 13:30:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Restrict-Export-of-Sensitive-Data/m-p/329276#M5943</guid>
      <dc:creator>IRHM73</dc:creator>
      <dc:date>2017-04-13T13:30:03Z</dc:date>
    </item>
  </channel>
</rss>

