<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restrict search to a role using  a search restriction is not working in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509956#M142563</link>
    <description>&lt;P&gt;No response yet, still investigating on the issue.&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jul 2020 05:53:05 GMT</pubDate>
    <dc:creator>MLGSPLUNK</dc:creator>
    <dc:date>2020-07-20T05:53:05Z</dc:date>
    <item>
      <title>Restrict search to a role using  a search restriction is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509023#M142215</link>
      <description>&lt;P&gt;Hi All.&lt;/P&gt;&lt;P&gt;I have a local instance on my laptop for demo purposes, so no complex deployment on this machine.&lt;/P&gt;&lt;P&gt;I have created an eventype="event1" wich should be used on search filtering terms for a role in order to restrict searches.&lt;/P&gt;&lt;P&gt;I then create a role named "role1":&lt;/P&gt;&lt;P&gt;1. Inheritance: none&lt;/P&gt;&lt;P&gt;2. Capabilities:&amp;nbsp; run_collect, run_mcollect, schedule_rtsearch, search&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Indexes: main&lt;/P&gt;&lt;P&gt;4. Restrictions:&amp;nbsp;(index::main) AND (sourcetype::source) AND (eventtype::event1) - If tested, this spl correctly returns the results I want the role to be able to search on&lt;/P&gt;&lt;P&gt;5. Resources: Nothing changed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I then save the role and assign it to the demo user. I also restarted splunk as docs says.&lt;/P&gt;&lt;P&gt;When I login with demo user, I can see all the events and is not filtering by the restrictions of its role.&lt;/P&gt;&lt;P&gt;Any clue on this?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 10:05:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509023#M142215</guid>
      <dc:creator>MLGSPLUNK</dc:creator>
      <dc:date>2020-07-14T10:05:38Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict search to a role using  a search restriction is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509028#M142217</link>
      <description>&lt;P&gt;Which kind of instance you have (trial, dev, full, ....)?&lt;BR /&gt;Some of those have &amp;nbsp;restrictions for which kind of users they have.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 10:19:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509028#M142217</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-07-14T10:19:26Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict search to a role using  a search restriction is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509030#M142219</link>
      <description>&lt;P&gt;I have a full license, and followed the docs to the heart as usual.&lt;/P&gt;&lt;P&gt;At now I only am using two users: admin and the restricted one.&lt;/P&gt;&lt;P&gt;As stated on my initial post, no role has been inherited for the demo user.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 10:24:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509030#M142219</guid>
      <dc:creator>MLGSPLUNK</dc:creator>
      <dc:date>2020-07-14T10:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict search to a role using  a search restriction is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509034#M142221</link>
      <description>&lt;P&gt;Can you share your authorize and authentication conf files?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 10:34:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509034#M142221</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-07-14T10:34:42Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict search to a role using  a search restriction is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509041#M142223</link>
      <description>&lt;P&gt;Authorize.conf&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# Version 8.0.1&lt;BR /&gt;# DO NOT EDIT THIS FILE!&lt;BR /&gt;# Changes to default files will be lost on update and are difficult to&lt;BR /&gt;# manage and support.&lt;BR /&gt;#&lt;BR /&gt;# Please make any changes to system defaults by overriding them in&lt;BR /&gt;# apps or $SPLUNK_HOME/etc/system/local&lt;BR /&gt;# (See "Configuration file precedence" in the web documentation).&lt;BR /&gt;#&lt;BR /&gt;# To override a specific setting, copy the name of the stanza and&lt;BR /&gt;# setting to the file where you wish to override it.&lt;BR /&gt;#&lt;BR /&gt;# commented out capabilities that are registered by their own components.&lt;BR /&gt;# leaving here for educational purposes.&lt;/P&gt;&lt;P&gt;# This file creates roles and sets granular access controls.&lt;/P&gt;&lt;P&gt;# These stanzas list all the capabilities in the system&lt;BR /&gt;[capability::accelerate_datamodel]&lt;BR /&gt;[capability::admin_all_objects]&lt;BR /&gt;[capability::edit_tokens_settings]&lt;BR /&gt;[capability::change_authentication]&lt;BR /&gt;[capability::change_own_password]&lt;BR /&gt;[capability::list_storage_passwords]&lt;BR /&gt;[capability::delete_by_keyword]&lt;BR /&gt;[capability::edit_bookmarks_mc]&lt;BR /&gt;[capability::edit_deployment_client]&lt;BR /&gt;[capability::list_deployment_client]&lt;BR /&gt;[capability::edit_deployment_server]&lt;BR /&gt;[capability::list_deployment_server]&lt;BR /&gt;[capability::edit_cmd]&lt;BR /&gt;[capability::edit_upload_and_index]&lt;BR /&gt;[capability::edit_tcp_stream]&lt;BR /&gt;[capability::list_dist_peer]&lt;BR /&gt;[capability::edit_dist_peer]&lt;BR /&gt;[capability::edit_forwarders]&lt;BR /&gt;[capability::edit_indexerdiscovery]&lt;BR /&gt;[capability::edit_httpauths]&lt;BR /&gt;[capability::edit_indexer_cluster]&lt;BR /&gt;[capability::edit_input_defaults]&lt;BR /&gt;[capability::install_apps]&lt;BR /&gt;[capability::edit_local_apps]&lt;BR /&gt;[capability::edit_authentication_extensions]&lt;BR /&gt;[capability::edit_monitor]&lt;BR /&gt;[capability::edit_restmap]&lt;BR /&gt;[capability::edit_roles]&lt;BR /&gt;[capability::edit_roles_grantable]&lt;BR /&gt;[capability::edit_scripted]&lt;BR /&gt;[capability::edit_search_server]&lt;BR /&gt;[capability::edit_search_head_clustering]&lt;BR /&gt;[capability::edit_search_concurrency_all]&lt;BR /&gt;[capability::edit_search_concurrency_scheduled]&lt;BR /&gt;[capability::edit_search_scheduler]&lt;BR /&gt;[capability::edit_search_schedule_priority]&lt;BR /&gt;[capability::edit_search_schedule_window]&lt;BR /&gt;[capability::list_pipeline_sets]&lt;BR /&gt;[capability::list_search_scheduler]&lt;BR /&gt;[capability::list_introspection]&lt;BR /&gt;[capability::list_settings]&lt;BR /&gt;[capability::list_metrics_catalog]&lt;BR /&gt;[capability::edit_tokens_all]&lt;BR /&gt;[capability::edit_tokens_own]&lt;BR /&gt;[capability::list_tokens_own]&lt;BR /&gt;[capability::edit_server]&lt;BR /&gt;[capability::edit_sourcetypes]&lt;BR /&gt;[capability::edit_splunktcp]&lt;BR /&gt;[capability::edit_splunktcp_ssl]&lt;BR /&gt;[capability::edit_splunktcp_token]&lt;BR /&gt;[capability::edit_statsd_transforms]&lt;BR /&gt;[capability::edit_metric_schema]&lt;BR /&gt;[capability::edit_tcp]&lt;BR /&gt;[capability::edit_udp]&lt;BR /&gt;[capability::edit_telemetry_settings]&lt;BR /&gt;[capability::edit_user]&lt;BR /&gt;[capability::edit_view_html]&lt;BR /&gt;[capability::edit_web_settings]&lt;BR /&gt;[capability::get_metadata]&lt;BR /&gt;[capability::get_typeahead]&lt;BR /&gt;[capability::get_diag]&lt;BR /&gt;[capability::indexes_edit]&lt;BR /&gt;[capability::input_file]&lt;BR /&gt;[capability::license_edit]&lt;BR /&gt;[capability::license_tab]&lt;BR /&gt;[capability::license_view_warnings]&lt;BR /&gt;[capability::list_forwarders]&lt;BR /&gt;[capability::list_indexerdiscovery]&lt;BR /&gt;[capability::list_httpauths]&lt;BR /&gt;[capability::list_indexer_cluster]&lt;BR /&gt;[capability::list_inputs]&lt;BR /&gt;[capability::list_search_head_clustering]&lt;BR /&gt;[capability::output_file]&lt;BR /&gt;[capability::request_remote_tok]&lt;BR /&gt;[capability::rest_apps_management]&lt;BR /&gt;[capability::rest_apps_view]&lt;BR /&gt;[capability::rest_properties_get]&lt;BR /&gt;[capability::rest_properties_set]&lt;BR /&gt;[capability::restart_splunkd]&lt;BR /&gt;[capability::restart_reason]&lt;BR /&gt;[capability::rtsearch]&lt;BR /&gt;[capability::run_debug_commands]&lt;BR /&gt;[capability::schedule_search]&lt;BR /&gt;[capability::metric_alerts]&lt;BR /&gt;[capability::schedule_rtsearch]&lt;BR /&gt;[capability::search]&lt;BR /&gt;[capability::use_file_operator]&lt;BR /&gt;[capability::accelerate_search]&lt;BR /&gt;[capability::list_accelerate_search]&lt;BR /&gt;[capability::run_multi_phased_searches]&lt;BR /&gt;[capability::embed_report]&lt;BR /&gt;[capability::pattern_detect]&lt;BR /&gt;[capability::edit_token_http]&lt;BR /&gt;[capability::web_debug]&lt;BR /&gt;[capability::export_results_is_visible]&lt;BR /&gt;[capability::edit_server_crl]&lt;BR /&gt;[capability::search_process_config_refresh]&lt;BR /&gt;[capability::dispatch_rest_to_indexers]&lt;BR /&gt;[capability::refresh_application_licenses]&lt;BR /&gt;[capability::edit_encryption_key_provider]&lt;BR /&gt;[capability::never_lockout]&lt;BR /&gt;[capability::never_expire]&lt;BR /&gt;[capability::list_health]&lt;BR /&gt;[capability::edit_health]&lt;BR /&gt;[capability::request_pstacks]&lt;BR /&gt;[capability::edit_watchdog]&lt;BR /&gt;[capability::list_workload_pools]&lt;BR /&gt;[capability::edit_workload_pools]&lt;BR /&gt;[capability::select_workload_pools]&lt;BR /&gt;[capability::list_workload_rules]&lt;BR /&gt;[capability::edit_workload_rules]&lt;BR /&gt;[capability::run_collect]&lt;BR /&gt;[capability::run_mcollect]&lt;BR /&gt;[capability::list_tokens_all]&lt;BR /&gt;[capability::upload_lookup_files]&lt;BR /&gt;[capability::apps_restore]&lt;BR /&gt;[capability::apps_backup]&lt;BR /&gt;[capability::edit_metrics_rollup]&lt;BR /&gt;[capability::list_cascading_plans]&lt;BR /&gt;[capability::run_msearch]&lt;BR /&gt;[capability::delete_messages]&lt;/P&gt;&lt;P&gt;[capability::edit_win_eventlogs]&lt;BR /&gt;[capability::edit_win_wmiconf]&lt;BR /&gt;[capability::edit_win_regmon]&lt;BR /&gt;[capability::edit_modinput_winhostmon]&lt;BR /&gt;[capability::edit_modinput_winnetmon]&lt;BR /&gt;[capability::edit_modinput_winprintmon]&lt;BR /&gt;[capability::edit_modinput_perfmon]&lt;BR /&gt;[capability::edit_modinput_admon]&lt;BR /&gt;[capability::list_win_localavailablelogs]&lt;BR /&gt;[capability::list_pdfserver]&lt;BR /&gt;[capability::write_pdfserver]&lt;/P&gt;&lt;P&gt;################################################################&lt;BR /&gt;################################################################&lt;BR /&gt;[default]&lt;BR /&gt;# ==== Subsumed roles ====&lt;BR /&gt;# ==== Capabilities ====&lt;BR /&gt;schedule_rtsearch = enabled&lt;BR /&gt;run_collect = enabled&lt;BR /&gt;run_mcollect = enabled&lt;BR /&gt;# ==== Other settings ====&lt;BR /&gt;srchDiskQuota = 100&lt;BR /&gt;srchJobsQuota = 3&lt;BR /&gt;rtSrchJobsQuota = 6&lt;BR /&gt;srchMaxTime = 100days&lt;BR /&gt;cumulativeSrchJobsQuota = 50&lt;BR /&gt;cumulativeRTSrchJobsQuota = 100&lt;BR /&gt;srchFilterSelecting = true&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;################################################################&lt;BR /&gt;################################################################&lt;BR /&gt;[role_user]&lt;BR /&gt;# ==== Subsumed roles ====&lt;BR /&gt;# ==== Capabilities ====&lt;BR /&gt;change_own_password = enabled&lt;BR /&gt;edit_search_schedule_window = enabled&lt;BR /&gt;get_metadata = enabled&lt;BR /&gt;get_typeahead = enabled&lt;BR /&gt;input_file = enabled&lt;BR /&gt;list_inputs = enabled&lt;BR /&gt;output_file = enabled&lt;BR /&gt;upload_lookup_files = enabled&lt;BR /&gt;request_remote_tok = enabled&lt;BR /&gt;rest_apps_view = enabled&lt;BR /&gt;rest_properties_get = enabled&lt;BR /&gt;rest_properties_set = enabled&lt;BR /&gt;search = enabled&lt;BR /&gt;accelerate_search = enabled&lt;BR /&gt;list_accelerate_search = enabled&lt;BR /&gt;pattern_detect = enabled&lt;BR /&gt;list_metrics_catalog = enabled&lt;BR /&gt;list_tokens_own = enabled&lt;BR /&gt;export_results_is_visible = enabled&lt;BR /&gt;run_collect = enabled&lt;BR /&gt;run_mcollect = enabled&lt;BR /&gt;delete_messages = enabled&lt;BR /&gt;# ==== Other settings ====&lt;BR /&gt;srchIndexesAllowed = *&lt;BR /&gt;srchIndexesDefault = main&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;################################################################&lt;BR /&gt;################################################################&lt;BR /&gt;[role_can_delete]&lt;BR /&gt;# ==== Subsumed roles ====&lt;BR /&gt;# ==== Capabilities ====&lt;BR /&gt;delete_by_keyword = enabled&lt;BR /&gt;# ==== Other settings ====&lt;BR /&gt;cumulativeSrchJobsQuota = 0&lt;BR /&gt;cumulativeRTSrchJobsQuota = 0&lt;BR /&gt;deleteIndexesAllowed = *&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;################################################################&lt;BR /&gt;################################################################&lt;BR /&gt;[role_power]&lt;BR /&gt;# ==== Subsumed roles ====&lt;BR /&gt;importRoles = user&lt;BR /&gt;# ==== Capabilities ====&lt;BR /&gt;schedule_search = enabled&lt;BR /&gt;metric_alerts = enabled&lt;BR /&gt;embed_report = enabled&lt;BR /&gt;rtsearch = enabled&lt;BR /&gt;edit_sourcetypes = enabled&lt;BR /&gt;edit_statsd_transforms = enabled&lt;BR /&gt;search_process_config_refresh = enabled&lt;BR /&gt;# ==== Other settings ====&lt;BR /&gt;srchIndexesAllowed = *&lt;BR /&gt;srchIndexesDefault = main&lt;BR /&gt;srchDiskQuota = 500&lt;BR /&gt;srchJobsQuota = 10&lt;BR /&gt;rtSrchJobsQuota = 20&lt;BR /&gt;cumulativeSrchJobsQuota = 100&lt;BR /&gt;cumulativeRTSrchJobsQuota = 200&lt;/P&gt;&lt;P&gt;################################################################&lt;BR /&gt;################################################################&lt;BR /&gt;[role_admin]&lt;BR /&gt;# ==== Subsumed roles ====&lt;BR /&gt;importRoles = power;user&lt;BR /&gt;# ==== Capabilities ====&lt;BR /&gt;accelerate_datamodel = enabled&lt;BR /&gt;admin_all_objects = enabled&lt;BR /&gt;edit_tokens_settings = enabled&lt;BR /&gt;change_authentication = enabled&lt;BR /&gt;edit_bookmarks_mc = enabled&lt;BR /&gt;edit_deployment_client = enabled&lt;BR /&gt;list_deployment_client = enabled&lt;BR /&gt;edit_deployment_server = enabled&lt;BR /&gt;list_deployment_server = enabled&lt;BR /&gt;list_search_head_clustering = enabled&lt;BR /&gt;dispatch_rest_to_indexers = enabled&lt;BR /&gt;edit_authentication_extensions = enabled&lt;BR /&gt;edit_cmd = enabled&lt;BR /&gt;edit_upload_and_index = enabled&lt;BR /&gt;edit_tcp_stream = enabled&lt;BR /&gt;list_dist_peer = enabled&lt;BR /&gt;edit_dist_peer = enabled&lt;BR /&gt;edit_restmap = enabled&lt;BR /&gt;edit_forwarders = enabled&lt;BR /&gt;edit_indexerdiscovery = enabled&lt;BR /&gt;edit_httpauths = enabled&lt;BR /&gt;edit_indexer_cluster = enabled&lt;BR /&gt;edit_input_defaults = enabled&lt;BR /&gt;edit_local_apps = enabled&lt;BR /&gt;edit_monitor = enabled&lt;BR /&gt;edit_tokens_own = enabled&lt;BR /&gt;edit_roles = enabled&lt;BR /&gt;edit_scripted = enabled&lt;BR /&gt;edit_search_concurrency_all = enabled&lt;BR /&gt;edit_search_head_clustering = enabled&lt;BR /&gt;edit_search_server = enabled&lt;BR /&gt;edit_search_scheduler = enabled&lt;BR /&gt;edit_search_schedule_priority = enabled&lt;BR /&gt;edit_tokens_all = enabled&lt;BR /&gt;list_tokens_all = enabled&lt;BR /&gt;list_indexer_cluster = enabled&lt;BR /&gt;list_pipeline_sets = enabled&lt;BR /&gt;list_search_scheduler = enabled&lt;BR /&gt;list_settings = enabled&lt;BR /&gt;edit_server = enabled&lt;BR /&gt;edit_splunktcp = enabled&lt;BR /&gt;edit_splunktcp_ssl = enabled&lt;BR /&gt;edit_splunktcp_token = enabled&lt;BR /&gt;edit_tcp = enabled&lt;BR /&gt;edit_udp = enabled&lt;BR /&gt;edit_telemetry_settings = enabled&lt;BR /&gt;edit_user = enabled&lt;BR /&gt;edit_view_html = enabled&lt;BR /&gt;edit_web_settings = enabled&lt;BR /&gt;get_diag = enabled&lt;BR /&gt;indexes_edit = enabled&lt;BR /&gt;install_apps = enabled&lt;BR /&gt;license_edit = enabled&lt;BR /&gt;license_tab = enabled&lt;BR /&gt;license_view_warnings = enabled&lt;BR /&gt;refresh_application_licenses = enabled&lt;BR /&gt;list_forwarders = enabled&lt;BR /&gt;list_indexerdiscovery = enabled&lt;BR /&gt;list_httpauths = enabled&lt;BR /&gt;rest_apps_management = enabled&lt;BR /&gt;restart_splunkd = enabled&lt;BR /&gt;restart_reason = enabled&lt;BR /&gt;run_debug_commands = enabled&lt;BR /&gt;edit_token_http = enabled&lt;BR /&gt;web_debug = enabled&lt;BR /&gt;edit_server_crl = enabled&lt;BR /&gt;list_storage_passwords = enabled&lt;BR /&gt;edit_encryption_key_provider = enabled&lt;BR /&gt;never_lockout = enabled&lt;BR /&gt;never_expire = enabled&lt;BR /&gt;list_health = enabled&lt;BR /&gt;edit_health = enabled&lt;BR /&gt;apps_restore = enabled&lt;BR /&gt;apps_backup = enabled&lt;BR /&gt;edit_workload_pools = enabled&lt;BR /&gt;list_workload_pools = enabled&lt;BR /&gt;select_workload_pools = enabled&lt;BR /&gt;edit_workload_rules = enabled&lt;BR /&gt;list_workload_rules = enabled&lt;BR /&gt;edit_metric_schema = enabled&lt;BR /&gt;edit_metrics_rollup = enabled&lt;BR /&gt;list_cascading_plans = enabled&lt;BR /&gt;edit_win_eventlogs = enabled&lt;BR /&gt;edit_win_wmiconf = enabled&lt;BR /&gt;edit_win_regmon = enabled&lt;BR /&gt;edit_modinput_winhostmon = enabled&lt;BR /&gt;edit_modinput_winnetmon = enabled&lt;BR /&gt;edit_modinput_winprintmon = enabled&lt;BR /&gt;edit_modinput_perfmon = enabled&lt;BR /&gt;edit_modinput_admon = enabled&lt;BR /&gt;list_win_localavailablelogs = enabled&lt;BR /&gt;list_pdfserver = enabled&lt;BR /&gt;write_pdfserver = enabled&lt;BR /&gt;run_msearch = enabled&lt;/P&gt;&lt;P&gt;# ==== Other settings ====&lt;BR /&gt;srchIndexesAllowed = *;_*&lt;BR /&gt;srchIndexesDefault = main;os&lt;BR /&gt;srchFilter = *&lt;BR /&gt;srchTimeWin = 0&lt;BR /&gt;srchDiskQuota = 10000&lt;BR /&gt;srchJobsQuota = 50&lt;BR /&gt;rtSrchJobsQuota = 100&lt;BR /&gt;cumulativeSrchJobsQuota = 200&lt;BR /&gt;cumulativeRTSrchJobsQuota = 400&lt;/P&gt;&lt;P&gt;################################################################&lt;BR /&gt;################################################################&lt;BR /&gt;[role_splunk-system-role]&lt;BR /&gt;# ==== Subsumed roles ====&lt;BR /&gt;importRoles = admin&lt;BR /&gt;# ==== Capabilities ====&lt;BR /&gt;# ==== Other settings ====&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;################################################################&lt;BR /&gt;################################################################&lt;BR /&gt;[tokens_auth]&lt;BR /&gt;expiration = never&lt;BR /&gt;disabled = true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 10:51:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509041#M142223</guid>
      <dc:creator>MLGSPLUNK</dc:creator>
      <dc:date>2020-07-14T10:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict search to a role using  a search restriction is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509042#M142224</link>
      <description>&lt;P&gt;authentication.conf&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# Version 8.0.1&lt;BR /&gt;# DO NOT EDIT THIS FILE!&lt;BR /&gt;# Changes to default files will be lost on update and are difficult to&lt;BR /&gt;# manage and support.&lt;BR /&gt;#&lt;BR /&gt;# Please make any changes to system defaults by overriding them in&lt;BR /&gt;# apps or $SPLUNK_HOME/etc/system/local&lt;BR /&gt;# (See "Configuration file precedence" in the web documentation).&lt;BR /&gt;#&lt;BR /&gt;# To override a specific setting, copy the name of the stanza and&lt;BR /&gt;# setting to the file where you wish to override it.&lt;BR /&gt;#&lt;BR /&gt;# This file configures authentication.&lt;/P&gt;&lt;P&gt;[authentication]&lt;BR /&gt;authType = Splunk&lt;BR /&gt;passwordHashAlgorithm = SHA512-crypt&lt;/P&gt;&lt;P&gt;# Note: the caching specified in this stanza only applies to scripted authentication.&lt;BR /&gt;# If you are using scripted authentication, you can override these cache timing values in&lt;BR /&gt;# your $SPLUNK_HOME\etc\system\local\authentication.conf&lt;BR /&gt;[cacheTiming]&lt;BR /&gt;userLoginTTL = 0&lt;BR /&gt;getUserInfoTTL = 10s&lt;BR /&gt;getUsersTTL = 10s&lt;/P&gt;&lt;P&gt;[secrets]&lt;BR /&gt;filename =&lt;BR /&gt;namespace = splunk&lt;/P&gt;&lt;P&gt;[splunk_auth]&lt;BR /&gt;minPasswordLength = 8&lt;BR /&gt;minPasswordUppercase = 0&lt;BR /&gt;minPasswordLowercase = 0&lt;BR /&gt;minPasswordSpecial = 0&lt;BR /&gt;minPasswordDigit = 0&lt;BR /&gt;expirePasswordDays = 90&lt;BR /&gt;expireAlertDays = 15&lt;BR /&gt;expireUserAccounts = false&lt;BR /&gt;forceWeakPasswordChange = false&lt;BR /&gt;lockoutUsers = true&lt;BR /&gt;lockoutAttempts = 5&lt;BR /&gt;lockoutThresholdMins = 5&lt;BR /&gt;lockoutMins = 30&lt;BR /&gt;enablePasswordHistory = false&lt;BR /&gt;passwordHistoryCount = 24&lt;BR /&gt;constantLoginTime = 0&lt;BR /&gt;verboseLoginFailMsg = true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 10:52:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509042#M142224</guid>
      <dc:creator>MLGSPLUNK</dc:creator>
      <dc:date>2020-07-14T10:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict search to a role using  a search restriction is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509048#M142228</link>
      <description>&lt;P&gt;Those seems to be the default versions, what we need to check are those in .../etc/system/local&lt;/P&gt;&lt;P&gt;and even better if you could get output of cmd “splunk btool authentication list —debug” and same for authorize config.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 11:29:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509048#M142228</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-07-14T11:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict search to a role using  a search restriction is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509051#M142230</link>
      <description>&lt;P&gt;Ok, my bad...they are really short&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;authentication.conf&lt;/P&gt;&lt;P&gt;[splunk_auth]&lt;BR /&gt;minPasswordLength=8&lt;BR /&gt;minPasswordUppercase=0&lt;BR /&gt;minPasswordLowercase=0&lt;BR /&gt;minPasswordSpecial=0&lt;BR /&gt;minPasswordDigit=0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;authorize.conf&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[role_user_no_privileges]&lt;BR /&gt;accelerate_search = disabled&lt;BR /&gt;cumulativeRTSrchJobsQuota = 0&lt;BR /&gt;cumulativeSrchJobsQuota = 0&lt;BR /&gt;search = enabled&lt;BR /&gt;srchFilter = (index::main) AND (sourcetype::cepsa) AND (eventtype::deposito1)&lt;BR /&gt;srchIndexesAllowed = main&lt;BR /&gt;srchMaxTime = 8640000&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 11:44:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509051#M142230</guid>
      <dc:creator>MLGSPLUNK</dc:creator>
      <dc:date>2020-07-14T11:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict search to a role using  a search restriction is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509052#M142231</link>
      <description>&lt;P&gt;Debug resutls&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[authentication]&lt;BR /&gt;authType = Splunk&lt;BR /&gt;passwordHashAlgorithm = SHA512-crypt&lt;BR /&gt;[cacheTiming]&lt;BR /&gt;getUserInfoTTL = 10s&lt;BR /&gt;getUsersTTL = 10s&lt;BR /&gt;userLoginTTL = 0&lt;BR /&gt;[secrets]&lt;BR /&gt;filename =&lt;BR /&gt;namespace = splunk&lt;BR /&gt;[splunk_auth]&lt;BR /&gt;constantLoginTime = 0&lt;BR /&gt;enablePasswordHistory = false&lt;BR /&gt;expireAlertDays = 15&lt;BR /&gt;expirePasswordDays = 90&lt;BR /&gt;expireUserAccounts = false&lt;BR /&gt;forceWeakPasswordChange = false&lt;BR /&gt;lockoutAttempts = 5&lt;BR /&gt;lockoutMins = 30&lt;BR /&gt;lockoutThresholdMins = 5&lt;BR /&gt;lockoutUsers = true&lt;BR /&gt;minPasswordDigit = 0&lt;BR /&gt;minPasswordLength = 8&lt;BR /&gt;minPasswordLowercase = 0&lt;BR /&gt;minPasswordSpecial = 0&lt;BR /&gt;minPasswordUppercase = 0&lt;BR /&gt;passwordHistoryCount = 24&lt;BR /&gt;verboseLoginFailMsg = true&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 11:50:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509052#M142231</guid>
      <dc:creator>MLGSPLUNK</dc:creator>
      <dc:date>2020-07-14T11:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict search to a role using  a search restriction is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509085#M142241</link>
      <description>&lt;P&gt;Someone suggested this could be a bug on Splunk 8.0.1.&lt;/P&gt;&lt;P&gt;Is this confirmed as a bug?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 14:46:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509085#M142241</guid>
      <dc:creator>MLGSPLUNK</dc:creator>
      <dc:date>2020-07-14T14:46:10Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict search to a role using  a search restriction is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509100#M142247</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;try to change&amp;nbsp;&lt;SPAN&gt;srchFilter = (index::main) to&amp;nbsp;srchFilter = (index=main) ....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;At least in earlier versions that was so.&amp;nbsp;&lt;BR /&gt;r. Ismo&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 16:56:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509100#M142247</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-07-14T16:56:20Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict search to a role using  a search restriction is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509191#M142300</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Changed to&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;(index=main) with no avail, still not working. Checked and updated the splunk version to 8.0.5 and its not working on latest either.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My guess is that this is a bug or something else is missing. Do you know how we can submit a bug to splunk so they can elaborate on? My other colleages at splunk team are clueless about the issue as well, and no info on internet differs of the method we are using.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks for your insights&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 07:30:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509191#M142300</guid>
      <dc:creator>MLGSPLUNK</dc:creator>
      <dc:date>2020-07-15T07:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict search to a role using  a search restriction is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509197#M142301</link>
      <description>&lt;P&gt;you should log to their support portal. This needs that you have valid entitlement and it has connected to your splunk.com account. If you haven’t that then you could ask someone else (who have those) to do it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;splunk.com -&amp;gt; support -&amp;gt; support portal Or something similar on top of page.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 08:11:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509197#M142301</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-07-15T08:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict search to a role using  a search restriction is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509205#M142303</link>
      <description>&lt;P&gt;Yeah, we have that at the company.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will post and will reply here as soon as I have more input.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 08:36:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509205#M142303</guid>
      <dc:creator>MLGSPLUNK</dc:creator>
      <dc:date>2020-07-15T08:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict search to a role using  a search restriction is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509956#M142563</link>
      <description>&lt;P&gt;No response yet, still investigating on the issue.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 05:53:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509956#M142563</guid>
      <dc:creator>MLGSPLUNK</dc:creator>
      <dc:date>2020-07-20T05:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict search to a role using  a search restriction is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509992#M142569</link>
      <description>&lt;P&gt;Hi all.&lt;/P&gt;&lt;P&gt;It seems that there was an issue with the license of Splunk I was using. After the license change, I restarted everything and it worked fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks all for the input.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 08:51:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509992#M142569</guid>
      <dc:creator>MLGSPLUNK</dc:creator>
      <dc:date>2020-07-20T08:51:26Z</dc:date>
    </item>
  </channel>
</rss>

