Alerting

What is the best practice for restricting users from seeing Splunk alerts and reports?

Federica_92
Communicator

Hi everyone,

I was wondering which is the best practice to follow to not allow everyone to see the Splunk alerts and the Splunk reports.

I created 50 alerts that are running as admin, and they are global. I need them to run on all the data, but I don't want all the users able to see them.
I also created 2 users with restrictions on the access, so that they shouldn't be able to see the alerts and the reports.

Is there a best practice to follow in a situation when you want to limit everyone from seeing the searches?

0 Karma

asimagu
Builder

Hi mate

According to Splunk, the best practice would be to play with permissions of the knowledge objects and setting up user roles.

http://docs.splunk.com/Documentation/Splunk/6.3.3/Security/SecuringaccessforSplunkknowledgeobjects

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...