Deployment Architecture

Restrict searches from unowned search head in indexer cluster

cwilmoth
Path Finder

We have a 3 node indexer cluster with one search head. We have allowed another team to connect their search head to our cluster so that they can pull certain statistics. Is there a way to restrict what they are allowed to search (namely disable real-time search ability)? We have control over our search head as far as what users can do, but we don't have any control over their search head configuration. We used to be able to restrict them when they connected via distributed search (needed a valid user/role on our end), but now that they are using clustering (only need the secret key to join) we don't have that option anymore.

Thanks.

0 Karma

yannK
Splunk Employee
Splunk Employee

No, the search restrictions are controlled by their search-head, so they can allow access to what they want.

If you were the admin of their SH, you could enforce role permissions and restrictions.

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...