All Apps and Add-ons

What si "All non Internal Indexes" in splunk, that is present under Indexes in a Role

sarnagar
Contributor

1) Firstly
Whats the difference between
"All non Internal Indexes"
and
"All Internal Indexes"
2)

I have 3 Roles "A" and "B" and "C"

Role "A" - with
Capabilities-
accelerate_search
change_own_password
edit_search_schedule_window
export_results_is_visible
extra_x509_validation
get_metadata
get_typeahead
input_file
output_file
pattern_detect
request_remote_tok
rest_apps_view
rest_properties_get
rest_properties_set
schedule_rtsearch
search
Default index - main
the Indexes selected as "All non Internal Indexes"

Role B
inherit role: A
Capability:
schedule_search
rtsearch
Index Default: A
Indexes: A, B

Role C;
inherit role: A
Capability:
schedule_search
rtsearch
Indexes default: C
Indexes: B,C

A test user1 with role A can view index A
user2 with role B can view index A
But user3 with role C cant view index A.
Why? user3 inherits Role A

0 Karma

teunlaan
Contributor

"All non Internal Indexes" = All indexes but NOT _* indexes
"All Internal Indexes" = All _* indexes (splunks own indexes)

user3 should have access too index A

Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...