Knowledge Management

Field limitation based on the user


Hi All,
Overview :
I am receiving logs from 40 fortigate firewall devices across the world and all are being indexed into same index , as of now we prepared dashboards and enabled dropdown based on the devicename(location) field present in the log.

Question : I have a situation like i need to restrict the dashboards to users based on the "devicename". meaning the user from a location must see only their location specific devicelogs , not others
Is it possible to restrict the user access by fieldvalue?

Labels (2)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...