<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to keep my rules to myself? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267850#M189914</link>
    <description>&lt;P&gt;what do you mean by rules?&lt;/P&gt;</description>
    <pubDate>Thu, 08 Oct 2015 19:46:41 GMT</pubDate>
    <dc:creator>muebel</dc:creator>
    <dc:date>2015-10-08T19:46:41Z</dc:date>
    <item>
      <title>how to keep my rules to myself?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267849#M189913</link>
      <description>&lt;P&gt;I'd like to know if it's possible to hide my rules from an admin user.&lt;/P&gt;

&lt;P&gt;Here's the situation:&lt;/P&gt;

&lt;P&gt;I'm not admin, however I can make rules for the Splunk, and I'd like that only could see it.&lt;BR /&gt;
So, even the administrator can't copy my rules, so I can keep my work just with myself.&lt;BR /&gt;
If anyone has any idea, I'd appreciate it .&lt;/P&gt;

&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 19:33:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267849#M189913</guid>
      <dc:creator>felipecg</dc:creator>
      <dc:date>2015-10-08T19:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: how to keep my rules to myself?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267850#M189914</link>
      <description>&lt;P&gt;what do you mean by rules?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 19:46:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267850#M189914</guid>
      <dc:creator>muebel</dc:creator>
      <dc:date>2015-10-08T19:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: how to keep my rules to myself?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267851#M189915</link>
      <description>&lt;P&gt;I meant I get the logs and create alerts, using a specific IP or code, and I'd like that just me could see it, however I'm not the admin. I don't wanna even the admin can access my rules(alerts I've created).&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 19:53:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267851#M189915</guid>
      <dc:creator>felipecg</dc:creator>
      <dc:date>2015-10-08T19:53:04Z</dc:date>
    </item>
    <item>
      <title>Re: how to keep my rules to myself?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267852#M189916</link>
      <description>&lt;P&gt;It would defeat the object of being an administrator if the administrator did not have total access to the system.&lt;/P&gt;

&lt;P&gt;It also seems very destructive to refuse to collaborate with co-workers, especially those responsible for a service you are using.  If I was the administrator I'd be all the more curious about what it was you had to hide.&lt;/P&gt;

&lt;P&gt;And no.  An administrator can see everything, if they choose to go looking.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 20:00:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267852#M189916</guid>
      <dc:creator>grijhwani</dc:creator>
      <dc:date>2015-10-08T20:00:17Z</dc:date>
    </item>
    <item>
      <title>Re: how to keep my rules to myself?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267853#M189917</link>
      <description>&lt;P&gt;Any idea how can I do it? &lt;BR /&gt;
has any possible way?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 20:01:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267853#M189917</guid>
      <dc:creator>felipecg</dc:creator>
      <dc:date>2015-10-08T20:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: how to keep my rules to myself?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267854#M189918</link>
      <description>&lt;P&gt;Well I think I didn't explain the situation well. &lt;BR /&gt;
If u have a company to administrate the Splunk and also have another company which make the rules.&lt;BR /&gt;
I guess the company which make the rules doesn't want to expose its intelligence, right? &lt;BR /&gt;
So, those are my rules, i just don't want that another company look at.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 20:10:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267854#M189918</guid>
      <dc:creator>felipecg</dc:creator>
      <dc:date>2015-10-08T20:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: how to keep my rules to myself?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267855#M189919</link>
      <description>&lt;P&gt;Actually the company responsible for admin the Splunk is not the same to make the rules. So, the company responsible to create the alerts  wants to keep its intelligence.  &lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 20:19:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267855#M189919</guid>
      <dc:creator>felipecg</dc:creator>
      <dc:date>2015-10-08T20:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: how to keep my rules to myself?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267856#M189920</link>
      <description>&lt;P&gt;Hi felipecg, unfortunately there isn't any way to prevent a user in the admin role from viewing knowledge objects (alerts, searches, views etc). Additionally, any user with root access to the servers running Splunk will be able to view these objects through the config files.&lt;/P&gt;

&lt;P&gt;The best you could do would be to load these configs into splunk as needed, and then delete them when not needed. Or maybe gain some obsecurity by creating many such objects.&lt;/P&gt;

&lt;P&gt;Let me know if this helps!&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 21:05:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267856#M189920</guid>
      <dc:creator>muebel</dc:creator>
      <dc:date>2015-10-08T21:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: how to keep my rules to myself?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267857#M189921</link>
      <description>&lt;P&gt;Well, I would like to hide because the company which admins the splunk it's not the company which makes the rules. I know it's not common.&lt;BR /&gt;
That's why I'd like to hide it.&lt;/P&gt;

&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 21:20:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267857#M189921</guid>
      <dc:creator>felipecg</dc:creator>
      <dc:date>2015-10-08T21:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: how to keep my rules to myself?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267858#M189922</link>
      <description>&lt;P&gt;ahh a specific use case.&lt;/P&gt;

&lt;P&gt;I think your out of luck honestly. As muebel said, someone with shell access can always get access to the machine and read your configs.&lt;/P&gt;

&lt;P&gt;Your alternative could be your own splunk cloud instance &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://blogs.splunk.com/wp-content/uploads/2015/09/ThreeClicks2.jpg.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 22:24:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267858#M189922</guid>
      <dc:creator>Lucas_K</dc:creator>
      <dc:date>2015-10-08T22:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: how to keep my rules to myself?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267859#M189923</link>
      <description>&lt;P&gt;OK, well I understand your problem, but regardless of the intent or motivation the reality doesn't change.  Regardless of the fact someone didn't like my original answer, the fact remains it can't be done.&lt;/P&gt;

&lt;P&gt;You can't do it with file permissions, because Splunk as an entirety runs as the same system user (more often than not with sysadmin rights which will override any permissions anyway), and at the application level a user account with administration privileges has total access to everything within the application.&lt;/P&gt;

&lt;P&gt;Short of setting up a dedicated Splunk search head administered by the right people, you simply cannot ring-fence the data.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 22:25:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267859#M189923</guid>
      <dc:creator>grijhwani</dc:creator>
      <dc:date>2015-10-08T22:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: how to keep my rules to myself?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267860#M189924</link>
      <description>&lt;P&gt;Which is a fair enough expectation honestly.&lt;/P&gt;

&lt;P&gt;No possibility to run your own search head to connect to the existing indexers?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 22:28:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267860#M189924</guid>
      <dc:creator>Lucas_K</dc:creator>
      <dc:date>2015-10-08T22:28:55Z</dc:date>
    </item>
    <item>
      <title>Re: how to keep my rules to myself?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267861#M189925</link>
      <description>&lt;P&gt;hey buddy,&lt;/P&gt;

&lt;P&gt;I have a problem like that and I solved with an external lookup. That way, you'll just need a single search on splunk and the verification stay on other host (that you control). If you do this on a local network, the delay will be minimum.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Oct 2015 13:09:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267861#M189925</guid>
      <dc:creator>renatobamorim</dc:creator>
      <dc:date>2015-10-09T13:09:42Z</dc:date>
    </item>
    <item>
      <title>Re: how to keep my rules to myself?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267862#M189926</link>
      <description>&lt;P&gt;Oh Snap! That's a good call.&lt;BR /&gt;
Thanks for your help.&lt;BR /&gt;
Also thank you guys for the others ideas.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Oct 2015 13:44:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267862#M189926</guid>
      <dc:creator>felipecg</dc:creator>
      <dc:date>2015-10-09T13:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: how to keep my rules to myself?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267863#M189927</link>
      <description>&lt;P&gt;That doesn't help you, at least not greatly.  The search is still going to appear in the logs when it is executed.  It only obscures it from direct view in the UI, so again, any administrator will be able to see it with ease if they choose to go looking.  It still doesn't provide a total solution.&lt;/P&gt;</description>
      <pubDate>Sun, 11 Oct 2015 16:46:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267863#M189927</guid>
      <dc:creator>grijhwani</dc:creator>
      <dc:date>2015-10-11T16:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: how to keep my rules to myself?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267864#M189928</link>
      <description>&lt;P&gt;Hi, grijhwani&lt;/P&gt;

&lt;P&gt;I agree that the search still able to admin, but I think that felipecg want to hide how he detects some anomalies, like SQLi, XSS, Padding Oracle from other firm.&lt;/P&gt;

&lt;P&gt;I have a similar scenario here, 1 splunk and 2 rival companies to administrate, its a nightmare.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2015 19:38:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-keep-my-rules-to-myself/m-p/267864#M189928</guid>
      <dc:creator>renatobamorim</dc:creator>
      <dc:date>2015-10-14T19:38:25Z</dc:date>
    </item>
  </channel>
</rss>

