Getting Data In

block any search for index=* with workload

bmcaetano
Engager

I'm trying to create an admission rule in workload management with the following syntax:

any search with "=*" in the index will return a predefined message.

my intention is to block any search that contains "=*" in any part of the index, such as: "index=splun*", "index=spl*", "index=_internal*", etc.

I didn't find anything in the documentation that talked about it. Is there any way to create a general rule for this case?

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

That use case is not supported by WLM admission rules.  Go to https://ideas.splunk.com to make a case for it.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

chrisboy68
Contributor

Reading through the Ideas, there are a few written different ways that will yield the same result. This is the simplest explanation, https://ideas.splunk.com/ideas/PLECID-I-606. If we can use * as a literal, then it will help your problem too. What would be best is to be able to implement a regex statement. At my shop, it would be ok to do index=ABCDE*, but not index=A*.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

That use case is not supported by WLM admission rules.  Go to https://ideas.splunk.com to make a case for it.

---
If this reply helps you, Karma would be appreciated.
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...