- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Restrict REST access to a specific index
rmorlen

Splunk Employee
10-24-2012
01:38 PM
We have defined a role:
[role_rest_role]
importRoles = can_delete;user
rtSrchJobsQuota = 0
srchDiskQuota = 0
srchIndexesAllowed = indexA
srchIndexesDefault = indexA
srchJobsQuota = 0
We have created a local user that has this role. The problem is that doing a search using REST the user has access to index=main. Since this user "can_delete" we really want to restrict their access to a specific index.
Any ideas?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ayn
Legend
10-24-2012
01:50 PM
It inherits the user role - doesn't this role have access to index main? If so, you need to remove this inheritance.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
rmorlen

Splunk Employee
10-25-2012
06:58 AM
Yes, this appears to have been the problem.
Thanks.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
rmorlen

Splunk Employee
10-25-2012
06:54 AM
I suspected this. Trying this today. I will post a response on the results.
Thanks.
