<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is Restrict Search Terms not working in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-is-Restrict-Search-Terms-not-working/m-p/263042#M78944</link>
    <description>&lt;P&gt;Dflodstrom is correct; there is a conflict with the inherited role, but you don't have to remove the inherited role to resolve the conflict. Rather than clear the restrict search term value, you have to replace it with a value. If you want no restrictions, replace the value with a "*" which will override the parameter's value from the inherited role. &lt;/P&gt;</description>
    <pubDate>Tue, 05 Nov 2019 15:09:52 GMT</pubDate>
    <dc:creator>Kyle_Sandoval</dc:creator>
    <dc:date>2019-11-05T15:09:52Z</dc:date>
    <item>
      <title>Why is Restrict Search Terms not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-Restrict-Search-Terms-not-working/m-p/263040#M78942</link>
      <description>&lt;P&gt;I want to restrict a given role's access to the data in Splunk by using 'Restrict search terms' under access controls.  First I tried to restrict based on tag...ie. tag=mytag.  This didn't work, so I tried to restrict on one host value...ie. host=hostname.  This isn't working either.&lt;/P&gt;

&lt;P&gt;I am attempting this on a standalone search head in a distributed environment with an indexer cluster.  I will apply this to my search head cluster when it is functional. It might also be useful to know that the role I'm modifying does have another role that is inherited which has its own restrict search terms configured.  We're using Splunk 6.3.0.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2016 16:46:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-Restrict-Search-Terms-not-working/m-p/263040#M78942</guid>
      <dc:creator>dflodstrom</dc:creator>
      <dc:date>2016-02-02T16:46:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Restrict Search Terms not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-Restrict-Search-Terms-not-working/m-p/263041#M78943</link>
      <description>&lt;P&gt;There must have been a conflict with using 'restrict search terms' on the role I was modifying and the inherited role.  I was able to resolve this issue by removing the inherited role.  Of course after doing this I needed to apply all of the settings from the inherited role to the role I was modifying.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2016 20:32:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-Restrict-Search-Terms-not-working/m-p/263041#M78943</guid>
      <dc:creator>dflodstrom</dc:creator>
      <dc:date>2016-02-04T20:32:15Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Restrict Search Terms not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-Restrict-Search-Terms-not-working/m-p/263042#M78944</link>
      <description>&lt;P&gt;Dflodstrom is correct; there is a conflict with the inherited role, but you don't have to remove the inherited role to resolve the conflict. Rather than clear the restrict search term value, you have to replace it with a value. If you want no restrictions, replace the value with a "*" which will override the parameter's value from the inherited role. &lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 15:09:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-Restrict-Search-Terms-not-working/m-p/263042#M78944</guid>
      <dc:creator>Kyle_Sandoval</dc:creator>
      <dc:date>2019-11-05T15:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Restrict Search Terms not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-Restrict-Search-Terms-not-working/m-p/263043#M78945</link>
      <description>&lt;P&gt;Dflodstrom is correct; the issue is the inherited role, but you don't have to remove the inherited role to resolve. You just need to set a value (any value) in the restrict search term parameter value. If it's blank, Splunk takes the inherited value from the role. Simply setting the value to '*' will override the inherited values. &lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 15:17:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-Restrict-Search-Terms-not-working/m-p/263043#M78945</guid>
      <dc:creator>Kyle_Sandoval</dc:creator>
      <dc:date>2019-11-05T15:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Restrict Search Terms not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-Restrict-Search-Terms-not-working/m-p/509216#M142304</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;I am running on the same issue as you did but on splunk 8.0.5. No roles are inherited and only search is granted to the user, but the search terms for the restrict search are not working at all and the user can see all the data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509197#M142301" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/Restrict-search-to-a-role-using-a-search-restriction-is-not/m-p/509197#M142301&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 09:11:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-Restrict-Search-Terms-not-working/m-p/509216#M142304</guid>
      <dc:creator>MLGSPLUNK</dc:creator>
      <dc:date>2020-07-15T09:11:03Z</dc:date>
    </item>
  </channel>
</rss>

