Deployment Architecture

Permission Distributed Search

Explorer

Hello,

Architecture:
I have a distributed Seach (not in Cluster)
1 Search head and 1 Indexer.

Every logs are stored on the indexer and with the search head user can search ....

Problem:
The problem is ... that I can allow a specific index per roles only on the indexer.
But user don't have an access to the indexer, they search via the GUI of the Search Head.

On the Search Head, I don't see the index create on the indexer, so the user have an access on every index
Is that possible to limit the access the search head ?

Thanks in advance

Tags (1)
0 Karma
1 Solution

SplunkTrust
SplunkTrust

place the indexes.conf on the search head as well
you are doing great by blocking the UI on the indexer

View solution in original post

0 Karma

SplunkTrust
SplunkTrust

place the indexes.conf on the search head as well
you are doing great by blocking the UI on the indexer

View solution in original post

0 Karma

Explorer

It works !
One more question, every time That I will create and index on the indexer , I have to create this to the search head too then ?

0 Karma

Ultra Champion

Yes, you would need to keep that configuration in sync.

Since you are not using clustering, in theory you could use a Deployment Server to centrally manage such configuration that needs to go to multiple systems. But setting that up just for this 1 config file might be a bit overkill.

Explorer

Ok thanks I will try to do this 🙂

0 Karma

SplunkTrust
SplunkTrust

@dalie, if it works for you, kindly accept the answer and up-vote helpful comments
cheers

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!