Knowledge Management

Datamodel dashboard view access without index permission

mmoermans
Path Finder

For security reasons there's users we don't want to give access to network indexes, yet they still need to view some things.
So in order to allow users to search for specific things we're trying to set up a dashboard which uses the Network_Traffic datamodel and shows results.

Yet whatever permissions I set none work for the user to view the datamodel results (No access to index, read rights to datamodel).

How do you set this up?

Tags (1)

rjthibod
Champion

To my knowledge, there is no way you can let them access the data directly. This is because the datamodel doesn't know if the data is going to be accelerated or not when the unprivileged users access it, so the datamodel has to assume that it will need to access the raw index at some point when those users come calling.

My suggestions is you will need to either get the data those users need via a saved search that can then right out the data to another knowledge object or search artifact that those users can access, or you can run a scheduled saved search against the datamodel that writes the data the unprivileged users will need to a summary index.

Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...