Knowledge Management

Datamodel dashboard view access without index permission

mmoermans
Path Finder

For security reasons there's users we don't want to give access to network indexes, yet they still need to view some things.
So in order to allow users to search for specific things we're trying to set up a dashboard which uses the Network_Traffic datamodel and shows results.

Yet whatever permissions I set none work for the user to view the datamodel results (No access to index, read rights to datamodel).

How do you set this up?

Tags (1)

rjthibod
Champion

To my knowledge, there is no way you can let them access the data directly. This is because the datamodel doesn't know if the data is going to be accelerated or not when the unprivileged users access it, so the datamodel has to assume that it will need to access the raw index at some point when those users come calling.

My suggestions is you will need to either get the data those users need via a saved search that can then right out the data to another knowledge object or search artifact that those users can access, or you can run a scheduled saved search against the datamodel that writes the data the unprivileged users will need to a summary index.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...