All Apps and Add-ons

After data is indexed from two different hosts, is there a way to filter on two search heads so teams only see their respective host's data?

RomeoG
New Member

We have a single indexer aggregating logs from our different teams.... Server, virtualization, Network, etc..... Generally, our teams use different apps. Unfortunately, I have 2 virtualization teams, each with their own Search Head, that use the Server Virtualization App, but from different hosts.

I am trying to figure out how I could filter on the respective search heads automatically so that each team sees only their hosts' data. Since the app uses custom indexes and source-types, I don't see a way to do it at index time. Any suggestions? Can this be done at search time on the search head?

0 Karma

vasanthmss
Motivator

Hi RomeoG,

Since you have already indexed the data in same index, create / update the roles with "Restrict search terms " parameter.

This may help you.

V
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...