Deployment Architecture

Restrict searches from unowned search head in indexer cluster

cwilmoth
Path Finder

We have a 3 node indexer cluster with one search head. We have allowed another team to connect their search head to our cluster so that they can pull certain statistics. Is there a way to restrict what they are allowed to search (namely disable real-time search ability)? We have control over our search head as far as what users can do, but we don't have any control over their search head configuration. We used to be able to restrict them when they connected via distributed search (needed a valid user/role on our end), but now that they are using clustering (only need the secret key to join) we don't have that option anymore.

Thanks.

0 Karma

yannK
Splunk Employee
Splunk Employee

No, the search restrictions are controlled by their search-head, so they can allow access to what they want.

If you were the admin of their SH, you could enforce role permissions and restrictions.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...