All Apps and Add-ons

How to restrict user access to certain reports and a specified time frame?

grambo271
Explorer

Greetings,

There is a compliance officer at my company that is making a lot of noise regarding the reports that the Active Directory application generates in 5.0.6. We want to give her access to run some reports herself but do not want to give her too much access (if you get my meaning). What I would like to do is to restrict her access to one or two reports and not allow her to access anything else. I’d also like to restrict her search abilities to 30 days maximum (otherwise she will cripple the search heads running All Time reports).

So my question is…. Is this possible? Is this an Active Directory group policy or can it be configured from the admin console? I have searched all over the admin console and roles but really didn't come up with anything of value. Am I missing something?

Any help or suggestions are appreciated.

1 Solution

derekarnold
Communicator

You can add search filters to a user group:

http://docs.splunk.com/Documentation/Splunk/6.1.2/Security/Addandeditroles

You can specify which indexes are searchable this way.

You can also restrict search time range to 30d or a preconfigured value. This can be accomplished in the Splunkweb user configuration page.

View solution in original post

derekarnold
Communicator

You can add search filters to a user group:

http://docs.splunk.com/Documentation/Splunk/6.1.2/Security/Addandeditroles

You can specify which indexes are searchable this way.

You can also restrict search time range to 30d or a preconfigured value. This can be accomplished in the Splunkweb user configuration page.

grambo271
Explorer

AWESOME!! Thank you!

0 Karma

derekarnold
Communicator

Yes you can restrict it at an app level as well. These two articles explain it better than I can since I'm currently just working off of my memory 🙂

http://docs.splunk.com/Documentation/Splunk/6.1.2/Security/Addmanagementaccesstocustomroles

http://docs.splunk.com/Documentation/Splunk/6.1.2/AdvancedDev/DefaultApp

somesoni2
Revered Legend

You can create a custom role (with the restrictions mentioned by @derekarnold). 2nd step will be configure permission for all applications to remove "Everyone" and just give to required roles. In this case your new restricted role will have only access to Active Directory App.

grambo271
Explorer

Thank you for such a fast response. I figured I was missing something. Is there a way to restrict compliance to a single app as well? I did not see that in the document you referenced.

Again thanks for your response

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...