<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Limit Users search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Limit-Users-search/m-p/447823#M126916</link>
    <description>&lt;P&gt;Yes you are correct, i am inheriting roles.&lt;/P&gt;

&lt;P&gt;Could you please suggest me if i use 1800 in this field for all the roles. I don`t want any user to search beyond 30 min.&lt;/P&gt;</description>
    <pubDate>Fri, 08 Feb 2019 08:05:26 GMT</pubDate>
    <dc:creator>ramprakash</dc:creator>
    <dc:date>2019-02-08T08:05:26Z</dc:date>
    <item>
      <title>Limit Users search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Limit-Users-search/m-p/447819#M126912</link>
      <description>&lt;P&gt;Hi Everyone...I want to put restrictions on users search as presently users can search for as long as they like. This could result in users executing searches for many hours.&lt;/P&gt;

&lt;P&gt;I tried to change this setting in Roles area but it is not working even after starting splunk.&lt;/P&gt;

&lt;P&gt;Restrict Search time range &lt;/P&gt;

&lt;P&gt;Set a maximum time window (in seconds) for searches for this role. For example, set this to '60' to restrict this role's searches to 1 minute before the most recent time specified in the search. You can also set this to '0' to explicitly make the window infinite, or '-1' to unset the window for this role (can be overridden by imported roles).&lt;/P&gt;

&lt;P&gt;I put 30 that means 30 sec and it is not working. Users can search beyond 30 sec. Can someone help ?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2019 09:33:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Limit-Users-search/m-p/447819#M126912</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2019-02-07T09:33:02Z</dc:date>
    </item>
    <item>
      <title>Re: Limit Users search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Limit-Users-search/m-p/447820#M126913</link>
      <description>&lt;P&gt;Hello @ramprakash&lt;/P&gt;

&lt;P&gt;I have tried this setting and it working perfectly. are you inheriting any role like user, power as these role will override this setting as mentioned above.&lt;/P&gt;

&lt;P&gt;create a role and just add search capability and &lt;CODE&gt;Restrict Search time range&lt;/CODE&gt; and try. &lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2019 10:50:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Limit-Users-search/m-p/447820#M126913</guid>
      <dc:creator>vishaltaneja070</dc:creator>
      <dc:date>2019-02-07T10:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: Limit Users search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Limit-Users-search/m-p/447821#M126914</link>
      <description>&lt;P&gt;Also be aware of an entirely new feature in Splunk v7.2 called &lt;CODE&gt;Workload Management&lt;/CODE&gt;:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.3/Workloads/Aboutworkloadmanagement"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.3/Workloads/Aboutworkloadmanagement&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2019 15:52:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Limit-Users-search/m-p/447821#M126914</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-02-07T15:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: Limit Users search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Limit-Users-search/m-p/447822#M126915</link>
      <description>&lt;P&gt;Okay my splunk version is 6.6.1&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 07:58:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Limit-Users-search/m-p/447822#M126915</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2019-02-08T07:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: Limit Users search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Limit-Users-search/m-p/447823#M126916</link>
      <description>&lt;P&gt;Yes you are correct, i am inheriting roles.&lt;/P&gt;

&lt;P&gt;Could you please suggest me if i use 1800 in this field for all the roles. I don`t want any user to search beyond 30 min.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 08:05:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Limit-Users-search/m-p/447823#M126916</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2019-02-08T08:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: Limit Users search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Limit-Users-search/m-p/447824#M126917</link>
      <description>&lt;P&gt;@ramprakash &lt;/P&gt;

&lt;P&gt;yes you can I have tried till 600 that was working good.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 08:13:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Limit-Users-search/m-p/447824#M126917</guid>
      <dc:creator>vishaltaneja070</dc:creator>
      <dc:date>2019-02-08T08:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: Limit Users search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Limit-Users-search/m-p/447825#M126918</link>
      <description>&lt;P&gt;@vishaltaneja07011993 ..I created separate user to test the functionality but it is not working.&lt;/P&gt;

&lt;P&gt;Problem is if i query for logs between 25 and 28 Jan. I am only getting results of 28 Jan with these settings. I don`t know why this is not reflecting correctly.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 12:42:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Limit-Users-search/m-p/447825#M126918</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2019-02-08T12:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: Limit Users search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Limit-Users-search/m-p/447826#M126919</link>
      <description>&lt;P&gt;@ramprakash&lt;/P&gt;

&lt;P&gt;What is the value you have mentioned in &lt;CODE&gt;Restrict Search time range range&lt;/CODE&gt;?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 13:44:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Limit-Users-search/m-p/447826#M126919</guid>
      <dc:creator>vishaltaneja070</dc:creator>
      <dc:date>2019-02-08T13:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: Limit Users search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Limit-Users-search/m-p/447827#M126920</link>
      <description>&lt;P&gt;1800......&lt;/P&gt;</description>
      <pubDate>Sat, 09 Feb 2019 17:00:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Limit-Users-search/m-p/447827#M126920</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2019-02-09T17:00:55Z</dc:date>
    </item>
  </channel>
</rss>

