Getting Data In

Is it possible to create a role-based search filter on a specific index?

pkeller
Contributor

We'd like to grant access to an additional index to a role, but we only want the members to be able to view 2 sourcetypes in that index.

I added a role called: foo_filtered
I added a search filter of: "service=Amazon OR service=Ebay" to that role
I gave that role access to an index named "vendor"

Their existing role foo_mail has access to search the "mail" and "spam" indexes.

So, when I add the foo_filtered role to their group, ALL searches (regardless of index) apply the filter. I only want the filter applied if they're searching the "vendor" index.

Is this even possible?
Thank you

0 Karma
1 Solution

masonmorales
Influencer

This is not possible with the current version of Splunk, unfortunately. You can submit an enhancement request on the Support Portal and they might add it in the future though.

View solution in original post

0 Karma

masonmorales
Influencer

This is not possible with the current version of Splunk, unfortunately. You can submit an enhancement request on the Support Portal and they might add it in the future though.

0 Karma

wryanthomas
Contributor

Is this still true?

0 Karma
Get Updates on the Splunk Community!

Exciting News: The AppDynamics Community Joins Splunk!

Hello Splunkers,   I’d like to introduce myself—I’m Ryan, the former AppDynamics Community Manager, and I’m ...

The All New Performance Insights for Splunk

Splunk gives you amazing tools to analyze system data and make business-critical decisions, react to issues, ...

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...