Knowledge Management

Field limitation based on the user

krvamsireddy
Explorer

Hi All,
Overview :
I am receiving logs from 40 fortigate firewall devices across the world and all are being indexed into same index , as of now we prepared dashboards and enabled dropdown based on the devicename(location) field present in the log.

Question : I have a situation like i need to restrict the dashboards to users based on the "devicename". meaning the user from a location must see only their location specific devicelogs , not others
Is it possible to restrict the user access by fieldvalue?



Labels (2)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...