<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does splunk user should query data using Index value? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Does-splunk-user-should-query-data-using-Index-value/m-p/362543#M107112</link>
    <description>&lt;P&gt;Hi saifuddin9122,&lt;/P&gt;

&lt;P&gt;You can create macros for it. &lt;/P&gt;</description>
    <pubDate>Fri, 09 Feb 2018 05:25:21 GMT</pubDate>
    <dc:creator>p_gurav</dc:creator>
    <dc:date>2018-02-09T05:25:21Z</dc:date>
    <item>
      <title>Does splunk user should query data using Index value?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Does-splunk-user-should-query-data-using-Index-value/m-p/362542#M107111</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;

&lt;P&gt;can users in splunk query data without using the index defined in search query? i mean can user search data using the sourcetype without defining the index in query? if so where should i define this property. As we have number of indexes defined and our users does not have idea of indexes, we don't want to query results using the index.&lt;/P&gt;

&lt;P&gt;Thanks &lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2018 21:12:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Does-splunk-user-should-query-data-using-Index-value/m-p/362542#M107111</guid>
      <dc:creator>saifuddin9122</dc:creator>
      <dc:date>2018-02-08T21:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: Does splunk user should query data using Index value?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Does-splunk-user-should-query-data-using-Index-value/m-p/362543#M107112</link>
      <description>&lt;P&gt;Hi saifuddin9122,&lt;/P&gt;

&lt;P&gt;You can create macros for it. &lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2018 05:25:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Does-splunk-user-should-query-data-using-Index-value/m-p/362543#M107112</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-02-09T05:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: Does splunk user should query data using Index value?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Does-splunk-user-should-query-data-using-Index-value/m-p/362544#M107113</link>
      <description>&lt;P&gt;Yes you can (not recommended ) .  You need to make all you indexes "searched by default" &lt;/P&gt;

&lt;P&gt;Configure it in "Settings &amp;gt; Access Controls &amp;gt; Roles &amp;gt;  the_role_your users_belong_too""    option :  Indexes searched by default"&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:02:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Does-splunk-user-should-query-data-using-Index-value/m-p/362544#M107113</guid>
      <dc:creator>teunlaan</dc:creator>
      <dc:date>2020-09-29T18:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: Does splunk user should query data using Index value?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Does-splunk-user-should-query-data-using-Index-value/m-p/362545#M107114</link>
      <description>&lt;P&gt;I believe that just searching on source/sourcetype is fine, as long as the defaults are set correctly for your environment. I have worked in an environment where the index field was overloaded to search so that you could see similar data, but your defaults controlled what you saw just by searching on the source/sourcetype.&lt;/P&gt;

&lt;P&gt;You have to make sure that the roles your splunk user inherits does not have indexes that are selected by default that you do not want to have your splunk user have access to by default.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2018 13:49:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Does-splunk-user-should-query-data-using-Index-value/m-p/362545#M107114</guid>
      <dc:creator>klopez30</dc:creator>
      <dc:date>2018-02-09T13:49:35Z</dc:date>
    </item>
  </channel>
</rss>

