<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Access Control for Splunk DB Connect in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56411#M179864</link>
    <description>&lt;P&gt;We will look into this and consider per-database entitlements a feature for an upcoming release. Thanks for raising the issue.&lt;/P&gt;</description>
    <pubDate>Fri, 07 Dec 2012 17:30:17 GMT</pubDate>
    <dc:creator>Dan</dc:creator>
    <dc:date>2012-12-07T17:30:17Z</dc:date>
    <item>
      <title>Access Control for Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56400#M179853</link>
      <description>&lt;P&gt;Do I get it right that after the successful setup of the &lt;STRONG&gt;Splunk DB Connect&lt;/STRONG&gt; every Splunk user can access the configured databases? &lt;BR /&gt;
This is not acceptable for almost every environment. I wonder how to implement access control at least per external database on a role basis. It would be nice, if Splunk would implement this feature. You should be able to choose the Roles which are allowed to use an external database, don't you think?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Dec 2012 13:59:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56400#M179853</guid>
      <dc:creator>dabbank</dc:creator>
      <dc:date>2012-12-06T13:59:02Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control for Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56401#M179854</link>
      <description>&lt;P&gt;Can't you just set the permissions for the DB Connect application itself to only allow certain roles to access it? That's what I do and only the admin role can access the Splunk DB Connect interface, views, commands.&lt;/P&gt;

&lt;P&gt;I haven't set up lookups yet but I have set up multiple monitoring inputs that push data to different indexes. Indexes have their own permissions settings.&lt;/P&gt;

&lt;P&gt;These seem like obvious settings so I'm concerned that I'm missing something on my end and users can access the databases. Can you tell me specifically how all users access the configured db?&lt;/P&gt;

&lt;P&gt;Thanks,J&lt;/P&gt;</description>
      <pubDate>Thu, 06 Dec 2012 20:15:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56401#M179854</guid>
      <dc:creator>jpass</dc:creator>
      <dc:date>2012-12-06T20:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control for Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56402#M179855</link>
      <description>&lt;P&gt;To limit the access for the whole application to certain roles is of course no solution. The entitlement for a specific database is user dependent. I can not name a role with access to all databases. Application wide permissions render the DB Connect useless.&lt;BR /&gt;
I would like to grant the users e.g. R/O access to "their" databases so they can use "dbquery" and "lookup" within searches.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Dec 2012 07:23:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56402#M179855</guid>
      <dc:creator>dabbank</dc:creator>
      <dc:date>2012-12-07T07:23:18Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control for Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56403#M179856</link>
      <description>&lt;P&gt;How many databases do you access? Another solution could be to have multiple versions of the db connect app installed but renamed for their different purposes. Of course this is a bit of a hack, plus it would break any automatic updates.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Dec 2012 08:56:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56403#M179856</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-12-07T08:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control for Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56404#M179857</link>
      <description>&lt;P&gt;Not only do we run numerous database but I also want to implement separate entries using different users for the same database. Hereby I could use the database restrictions to adjust the capabilities for my Splunk users. I consider a separate instance for every access profile not even as workaround -- who knows about side effects and the waste of resources caused by this approach.&lt;BR /&gt;
The DB Connect application is from 2005 and does not support a proper rights management. Do we really talk about an enterprise solution?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Dec 2012 12:03:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56404#M179857</guid>
      <dc:creator>dabbank</dc:creator>
      <dc:date>2012-12-07T12:03:20Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control for Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56405#M179858</link>
      <description>&lt;P&gt;Uh, the DB connect is not from 2005, it was just released.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Dec 2012 12:44:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56405#M179858</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-12-07T12:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control for Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56406#M179859</link>
      <description>&lt;P&gt;All files of the app state&lt;BR /&gt;
&lt;STRONG&gt;Copyright (C) 2005-2012 Splunk Inc. All Rights Reserved.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Dec 2012 15:04:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56406#M179859</guid>
      <dc:creator>dabbank</dc:creator>
      <dc:date>2012-12-07T15:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control for Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56407#M179860</link>
      <description>&lt;P&gt;Thats the generic Splunk copyright, have a scroll to the bottom of the page. I believe thats probably the year it came into existence&lt;/P&gt;</description>
      <pubDate>Fri, 07 Dec 2012 15:44:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56407#M179860</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-12-07T15:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control for Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56408#M179861</link>
      <description>&lt;P&gt;I played with the app and found some interesting results:&lt;/P&gt;

&lt;P&gt;The permissions defined in &lt;EM&gt;etc/apps/dbx/metadata/default.meta&lt;/EM&gt; overule the settings in &lt;EM&gt;etc/apps/dbx/metadata/local.meta&lt;/EM&gt;. Therefore you can not use the WebGUI to adjust the access rights. E.g. only the role &lt;EM&gt;admin&lt;/EM&gt; can use the &lt;EM&gt;dbquery&lt;/EM&gt; command per default.&lt;BR /&gt;
I changed all role settings within the default file to "*" and now it works as expected.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Dec 2012 16:13:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56408#M179861</guid>
      <dc:creator>dabbank</dc:creator>
      <dc:date>2012-12-07T16:13:15Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control for Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56409#M179862</link>
      <description>&lt;P&gt;The settings in &lt;EM&gt;apps/search/metadata/local.meta&lt;/EM&gt; are respected half way. You can add an &lt;EM&gt;access&lt;/EM&gt;-line within the stanza for an external database connection&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;[database/MyDB]&lt;BR /&gt;
access = read : [ admin, db_admin ]&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;At least Splunk respects the read permissions while you edit the settings. E.g. if a user has no read access, he does not see the configured connection underneath &lt;EM&gt;External Databases&lt;/EM&gt;&lt;BR /&gt;
A lack of read permissions does not stop the user from using the external database within &lt;EM&gt;dbquery&lt;/EM&gt;, though.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Dec 2012 16:13:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56409#M179862</guid>
      <dc:creator>dabbank</dc:creator>
      <dc:date>2012-12-07T16:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control for Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56410#M179863</link>
      <description>&lt;P&gt;If a user should be able to configure database connections himself, he needs the &lt;EM&gt;admin_all_objects&lt;/EM&gt; capability in his role &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:55:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56410#M179863</guid>
      <dc:creator>dabbank</dc:creator>
      <dc:date>2020-09-28T12:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control for Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56411#M179864</link>
      <description>&lt;P&gt;We will look into this and consider per-database entitlements a feature for an upcoming release. Thanks for raising the issue.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Dec 2012 17:30:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56411#M179864</guid>
      <dc:creator>Dan</dc:creator>
      <dc:date>2012-12-07T17:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control for Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56412#M179865</link>
      <description>&lt;P&gt;any updates on this Dan?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2013 06:11:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56412#M179865</guid>
      <dc:creator>batcave</dc:creator>
      <dc:date>2013-02-06T06:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control for Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56413#M179866</link>
      <description>&lt;P&gt;This is high on the docket but I can't provide a timeframe yet&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2013 22:38:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Access-Control-for-Splunk-DB-Connect/m-p/56413#M179866</guid>
      <dc:creator>Dan</dc:creator>
      <dc:date>2013-02-12T22:38:49Z</dc:date>
    </item>
  </channel>
</rss>

