Installation

How to Assign Access Role to multiple groups

SplunkDash
Motivator

Hello,

I have a situation where there are 25 different groups  of people and each group of people uses different sets of data (i.e. there are 25 different sets of data, one for each group). We need to create a single dashboard and also need to assign access role in a way that each group can only have access to their data set using the same dashboard.   How I would assign the access role for those 25 different groups. 

Should I create 25 different indexes - one for  each group  and assign access role to those indexes?

Is it possible to create 25 different sourcetypes and assign access role to those sourcetypes  - one for each group and keep all sourcetypes under one index?

Or are there any other ways?

Thank you so  much, any help will be highly appreciated.

  

 

Tags (1)
0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

The permissions are granted on a per-index basis so if you want to limit the access to the data, you separate it into different indexes (it's one of the cases where splitting data into indexes is advisable).

If you want to use the same dashboard for different user groups (and thus indexes), you have to make it so that the source index used in searches is dynamically settable - not hardcoded.

View solution in original post

PickleRick
SplunkTrust
SplunkTrust

The permissions are granted on a per-index basis so if you want to limit the access to the data, you separate it into different indexes (it's one of the cases where splitting data into indexes is advisable).

If you want to use the same dashboard for different user groups (and thus indexes), you have to make it so that the source index used in searches is dynamically settable - not hardcoded.

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...