Deployment Architecture

Restrict searches from unowned search head in indexer cluster

cwilmoth
Path Finder

We have a 3 node indexer cluster with one search head. We have allowed another team to connect their search head to our cluster so that they can pull certain statistics. Is there a way to restrict what they are allowed to search (namely disable real-time search ability)? We have control over our search head as far as what users can do, but we don't have any control over their search head configuration. We used to be able to restrict them when they connected via distributed search (needed a valid user/role on our end), but now that they are using clustering (only need the secret key to join) we don't have that option anymore.

Thanks.

0 Karma

yannK
Splunk Employee
Splunk Employee

No, the search restrictions are controlled by their search-head, so they can allow access to what they want.

If you were the admin of their SH, you could enforce role permissions and restrictions.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...