All Apps and Add-ons

What si "All non Internal Indexes" in splunk, that is present under Indexes in a Role

sarnagar
Contributor

1) Firstly
Whats the difference between
"All non Internal Indexes"
and
"All Internal Indexes"
2)

I have 3 Roles "A" and "B" and "C"

Role "A" - with
Capabilities-
accelerate_search
change_own_password
edit_search_schedule_window
export_results_is_visible
extra_x509_validation
get_metadata
get_typeahead
input_file
output_file
pattern_detect
request_remote_tok
rest_apps_view
rest_properties_get
rest_properties_set
schedule_rtsearch
search
Default index - main
the Indexes selected as "All non Internal Indexes"

Role B
inherit role: A
Capability:
schedule_search
rtsearch
Index Default: A
Indexes: A, B

Role C;
inherit role: A
Capability:
schedule_search
rtsearch
Indexes default: C
Indexes: B,C

A test user1 with role A can view index A
user2 with role B can view index A
But user3 with role C cant view index A.
Why? user3 inherits Role A

0 Karma

teunlaan
Contributor

"All non Internal Indexes" = All indexes but NOT _* indexes
"All Internal Indexes" = All _* indexes (splunks own indexes)

user3 should have access too index A

Get Updates on the Splunk Community!

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...

Ready, Set, SOAR: How Utility Apps Can Up Level Your Playbooks!

 WATCH NOW Powering your capabilities has never been so easy with ready-made Splunk® SOAR Utility Apps. Parse ...

DevSecOps: Why You Should Care and How To Get Started

 WATCH NOW In this Tech Talk we will talk about what people mean by DevSecOps and deep dive into the different ...