<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Index restriction not working with search head and search peers in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Index-restriction-not-working-with-search-head-and-search-peers/m-p/87334#M22352</link>
    <description>&lt;P&gt;We have 1 search head with 2 search peers.  We have numerous indexes defined on the search peers, for example index A, B on the first peer and index C, D on the second peer.  Using the search head we are able to search all the indexes as expected.  We want to have our users perform all searches from the search head, however, when we define roles on our search head we are we are unable to see the remote indexes (index A,B,C,D) and thereby unable to restrict those indexes from any roles. Only the local indexes are showing within the Roles configuration screen.&lt;BR /&gt;&lt;BR /&gt;
what is the proper way to restrict users from searching those remote indexes?&lt;/P&gt;</description>
    <pubDate>Tue, 08 Oct 2013 14:09:35 GMT</pubDate>
    <dc:creator>takn4granted</dc:creator>
    <dc:date>2013-10-08T14:09:35Z</dc:date>
    <item>
      <title>Index restriction not working with search head and search peers</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Index-restriction-not-working-with-search-head-and-search-peers/m-p/87334#M22352</link>
      <description>&lt;P&gt;We have 1 search head with 2 search peers.  We have numerous indexes defined on the search peers, for example index A, B on the first peer and index C, D on the second peer.  Using the search head we are able to search all the indexes as expected.  We want to have our users perform all searches from the search head, however, when we define roles on our search head we are we are unable to see the remote indexes (index A,B,C,D) and thereby unable to restrict those indexes from any roles. Only the local indexes are showing within the Roles configuration screen.&lt;BR /&gt;&lt;BR /&gt;
what is the proper way to restrict users from searching those remote indexes?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2013 14:09:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Index-restriction-not-working-with-search-head-and-search-peers/m-p/87334#M22352</guid>
      <dc:creator>takn4granted</dc:creator>
      <dc:date>2013-10-08T14:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: Index restriction not working with search head and search peers</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Index-restriction-not-working-with-search-head-and-search-peers/m-p/87335#M22353</link>
      <description>&lt;P&gt;Define the indexes on the search head - even if they are entirely empty, this is okay.  That will make them appear in the manager UI on the search head so you can establish roles as needed.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2013 21:49:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Index-restriction-not-working-with-search-head-and-search-peers/m-p/87335#M22353</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2013-10-08T21:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: Index restriction not working with search head and search peers</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Index-restriction-not-working-with-search-head-and-search-peers/m-p/87336#M22354</link>
      <description>&lt;P&gt;Hi bro,&lt;BR /&gt;&lt;/P&gt;

&lt;P&gt;While creating new roles , please carefully add indexes to be searched/restricted for that particular role,&lt;BR /&gt;
Later assign that role to any user and you test.&lt;/P&gt;

&lt;P&gt;Goto ,&lt;BR /&gt;&lt;BR /&gt;
&lt;B&gt;Manager » Access controls » Roles » &lt;/B&gt;&lt;BR /&gt;&lt;/P&gt;

&lt;P&gt;&lt;B&gt;Indexes searched by default:&lt;/B&gt;(Set the index(es) that searches default to when no index is specified. User with this role can search other indexes using index= (e.g., "index=special_index").)&lt;/P&gt;

&lt;P&gt;&lt;B&gt;Indexes :&lt;/B&gt;(Restrict this role's searches to the specified index(es). Search results for this role will only show events from these indexes.)&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2014 02:58:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Index-restriction-not-working-with-search-head-and-search-peers/m-p/87336#M22354</guid>
      <dc:creator>chimbudp</dc:creator>
      <dc:date>2014-01-07T02:58:58Z</dc:date>
    </item>
  </channel>
</rss>

