All Apps and Add-ons

What si "All non Internal Indexes" in splunk, that is present under Indexes in a Role

sarnagar
Contributor

1) Firstly
Whats the difference between
"All non Internal Indexes"
and
"All Internal Indexes"
2)

I have 3 Roles "A" and "B" and "C"

Role "A" - with
Capabilities-
accelerate_search
change_own_password
edit_search_schedule_window
export_results_is_visible
extra_x509_validation
get_metadata
get_typeahead
input_file
output_file
pattern_detect
request_remote_tok
rest_apps_view
rest_properties_get
rest_properties_set
schedule_rtsearch
search
Default index - main
the Indexes selected as "All non Internal Indexes"

Role B
inherit role: A
Capability:
schedule_search
rtsearch
Index Default: A
Indexes: A, B

Role C;
inherit role: A
Capability:
schedule_search
rtsearch
Indexes default: C
Indexes: B,C

A test user1 with role A can view index A
user2 with role B can view index A
But user3 with role C cant view index A.
Why? user3 inherits Role A

0 Karma

teunlaan
Contributor

"All non Internal Indexes" = All indexes but NOT _* indexes
"All Internal Indexes" = All _* indexes (splunks own indexes)

user3 should have access too index A

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...