Getting Data In

Is there a way to grant access to a specific index within an app's authorize.conf?

cee137
Explorer

I have index1, index2, and index 3. I want role_user to have access to all three within a specific app. Is there a way to do this?

In $SPLUNK_HOME/etc/system/local my authorize.conf has 

srchIndexesDefault: index1;index2
srchIndexesAllowed: index1;index2

 In $SPLUNK_HOME/etc/apps/myApp/local my authorize.conf has 

srchIndexesDefault: index1;index2;index3
srchIndexesAllowed: index1;index2;index3

Of course, this doesn't work. I understand /system/local wins this conflicting parameter fight. Is there anyway to grant the user role access to index3 within myApp? Or would I have to create a different role that inherits role_user and adds index3 access to achieve this? 

Thanks in advance.

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Access to indexes is by role only, not by app.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Access to indexes is by role only, not by app.

---
If this reply helps you, Karma would be appreciated.
0 Karma

cee137
Explorer

Darn. Thanks for the concise response!

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...