<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Use the &amp;quot;restricted search terms&amp;quot; of a role to filter a saved search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Use-the-quot-restricted-search-terms-quot-of-a-role-to-filter-a/m-p/399389#M172984</link>
    <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;I have a saved search, running each day with the following output&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Computer_Name |&amp;nbsp;DPT | Install_status | Patch_ID&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;I have a dashboard in with a panel like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;Windows Patch Management&amp;lt;/title&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;title&amp;gt;Windows computers&amp;lt;/title&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;| loadjob savedsearch="MyUser:MyApp:WindowsPatches" 
| search $DPT$ | stats dc(Computer_Name)&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-30d@d&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
      &amp;lt;/single&amp;gt;
&amp;lt;/panel&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I'm facing a little issue here, I can filter using a dropdown, that's the "| search $DPT$ " where $DPT$ is a dropdown of Departments with the following Token value prefix : &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;DPT="&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;and the following Token value sufix &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;"&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;But I would like to reuse the  "restricted search terms" of the user which is, for exemple : DPT="IT" in order to really restrict and not only visually. I didn't find a topic on how to retrieve this specific field, any ideas ?&lt;/P&gt;

&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 23:21:48 GMT</pubDate>
    <dc:creator>mdtrandco</dc:creator>
    <dc:date>2020-09-29T23:21:48Z</dc:date>
    <item>
      <title>Use the "restricted search terms" of a role to filter a saved search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Use-the-quot-restricted-search-terms-quot-of-a-role-to-filter-a/m-p/399389#M172984</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;I have a saved search, running each day with the following output&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Computer_Name |&amp;nbsp;DPT | Install_status | Patch_ID&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;I have a dashboard in with a panel like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;Windows Patch Management&amp;lt;/title&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;title&amp;gt;Windows computers&amp;lt;/title&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;| loadjob savedsearch="MyUser:MyApp:WindowsPatches" 
| search $DPT$ | stats dc(Computer_Name)&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-30d@d&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
      &amp;lt;/single&amp;gt;
&amp;lt;/panel&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I'm facing a little issue here, I can filter using a dropdown, that's the "| search $DPT$ " where $DPT$ is a dropdown of Departments with the following Token value prefix : &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;DPT="&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;and the following Token value sufix &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;"&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;But I would like to reuse the  "restricted search terms" of the user which is, for exemple : DPT="IT" in order to really restrict and not only visually. I didn't find a topic on how to retrieve this specific field, any ideas ?&lt;/P&gt;

&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:21:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Use-the-quot-restricted-search-terms-quot-of-a-role-to-filter-a/m-p/399389#M172984</guid>
      <dc:creator>mdtrandco</dc:creator>
      <dc:date>2020-09-29T23:21:48Z</dc:date>
    </item>
    <item>
      <title>Re: Use the "restricted search terms" of a role to filter a saved search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Use-the-quot-restricted-search-terms-quot-of-a-role-to-filter-a/m-p/399390#M172985</link>
      <description>&lt;P&gt;Do not use those search restrictions using search-time fields if the application is security-relevant, they're easily bypassed.&lt;BR /&gt;
Similarly, do not use dashboard-based restrictions as those are under the control of the user's browser, and thereby easily bypassed as well.&lt;/P&gt;

&lt;P&gt;If it's just a convenience case with no security implications you can use the currently logged in user's context via &lt;CODE&gt;|rest&lt;/CODE&gt; to load its roles and associated search filters.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Feb 2019 16:36:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Use-the-quot-restricted-search-terms-quot-of-a-role-to-filter-a/m-p/399390#M172985</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2019-02-17T16:36:36Z</dc:date>
    </item>
    <item>
      <title>Re: Use the "restricted search terms" of a role to filter a saved search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Use-the-quot-restricted-search-terms-quot-of-a-role-to-filter-a/m-p/399391#M172986</link>
      <description>&lt;P&gt;Hi Martin, &lt;/P&gt;

&lt;P&gt;Thanks for your answer. If I have security in mind, what are the function I should look into ?&lt;/P&gt;

&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Sun, 17 Feb 2019 17:08:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Use-the-quot-restricted-search-terms-quot-of-a-role-to-filter-a/m-p/399391#M172986</guid>
      <dc:creator>mdtrandco</dc:creator>
      <dc:date>2019-02-17T17:08:25Z</dc:date>
    </item>
    <item>
      <title>Re: Use the "restricted search terms" of a role to filter a saved search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Use-the-quot-restricted-search-terms-quot-of-a-role-to-filter-a/m-p/399392#M172987</link>
      <description>&lt;P&gt;Index permissions per role and saved searches running as owner for indexes the users should not have full access to.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Feb 2019 17:45:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Use-the-quot-restricted-search-terms-quot-of-a-role-to-filter-a/m-p/399392#M172987</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2019-02-17T17:45:49Z</dc:date>
    </item>
  </channel>
</rss>

