Deployment Architecture

Restrict searches from unowned search head in indexer cluster

cwilmoth
Path Finder

We have a 3 node indexer cluster with one search head. We have allowed another team to connect their search head to our cluster so that they can pull certain statistics. Is there a way to restrict what they are allowed to search (namely disable real-time search ability)? We have control over our search head as far as what users can do, but we don't have any control over their search head configuration. We used to be able to restrict them when they connected via distributed search (needed a valid user/role on our end), but now that they are using clustering (only need the secret key to join) we don't have that option anymore.

Thanks.

0 Karma

yannK
Splunk Employee
Splunk Employee

No, the search restrictions are controlled by their search-head, so they can allow access to what they want.

If you were the admin of their SH, you could enforce role permissions and restrictions.

0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...