<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restricting users from search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Restricting-users-from-search/m-p/38713#M8811</link>
    <description>&lt;P&gt;You want user to able to log in but not able to perform search on specific period like 6:00 PM to 6:00 AM?&lt;/P&gt;</description>
    <pubDate>Fri, 05 Dec 2014 17:43:29 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2014-12-05T17:43:29Z</dc:date>
    <item>
      <title>Restricting users from search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Restricting-users-from-search/m-p/38711#M8809</link>
      <description>&lt;P&gt;We have a situation where we need to restrict users to be able to search during a specific period of time. Removing &lt;STRONG&gt;search=enabled&lt;/STRONG&gt; for a particular role in authorize.conf is not working. Is there a way we can achieve this for a role?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2013 13:06:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Restricting-users-from-search/m-p/38711#M8809</guid>
      <dc:creator>pradeepkumarg</dc:creator>
      <dc:date>2013-08-19T13:06:55Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting users from search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Restricting-users-from-search/m-p/38712#M8810</link>
      <description>&lt;P&gt;I don't believe there is a way to restrict user search access based on time. You could certainly remove the indexes that are searchable from a role to avoid users searching on specific/all data during a specific period.  That would require a restart of Splunk of course.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2013 17:56:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Restricting-users-from-search/m-p/38712#M8810</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2013-08-20T17:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting users from search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Restricting-users-from-search/m-p/38713#M8811</link>
      <description>&lt;P&gt;You want user to able to log in but not able to perform search on specific period like 6:00 PM to 6:00 AM?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Dec 2014 17:43:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Restricting-users-from-search/m-p/38713#M8811</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-12-05T17:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting users from search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Restricting-users-from-search/m-p/38714#M8812</link>
      <description>&lt;P&gt;Associated with the User Role, you could add a "Restrict search terms" filter. &lt;/P&gt;

&lt;P&gt;If for a very specific period in time you could add, for example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(_time&amp;gt;1417805142.703 AND _time&amp;lt;1417805242.703)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Or if you want to prevent people searching data between 18h00 and 19h00 you could add the filter:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;date_hour!=18
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 05 Dec 2014 18:55:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Restricting-users-from-search/m-p/38714#M8812</guid>
      <dc:creator>ayme</dc:creator>
      <dc:date>2014-12-05T18:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting users from search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Restricting-users-from-search/m-p/38715#M8813</link>
      <description>&lt;P&gt;@somesoni2 Right but the timings are not fixed, it's when we know that there is going to be a users storm logging in and issuing searches to solve a very high severity issue happening in the organization, it's at that point of time we want to restrict searching only for a critical team/role to save Splunk system resources from taking a toss.. &lt;/P&gt;</description>
      <pubDate>Thu, 22 Jan 2015 17:36:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Restricting-users-from-search/m-p/38715#M8813</guid>
      <dc:creator>pradeepkumarg</dc:creator>
      <dc:date>2015-01-22T17:36:48Z</dc:date>
    </item>
  </channel>
</rss>

