Monitoring Splunk

Can i restrict users accessing other apps ??

rakesh_498115
Motivator

Hi..

i have created two apps say MYAPP and GUESTAPP and have created a few user profiles to login to the splunk.I dont want these users to access the dashboards and forms that are in MYAPP i.e i dont want to give the users to access MYAPP . i Need to restrict their access to GUESTAPP alone...

How can i do it ?? thnx.

Tags (1)

jonuwz
Influencer

Create a role for this group of users. Put the user accounts in the role.

Go to Manager > Apps and change the permissions on each app as you see fit.

You will probably need to go through each app that is enabled, and change the read/write from 'everyone' to something more suited to your needs

yoho
Contributor

Is there any way to deny access to applications by default but only give access to selected applications for a specific role?

yannK
Splunk Employee
Splunk Employee

works only on splunk enteprise, not on splunk free.

  • first, you create a role, and eventually put users with that role.
  • go to you app settings (manager > apps > permissions) and put the permissions to only the members of this group (and admin at least) this will also be the default permissions to any object of this app (but you can probably change individually later)
0 Karma

rakesh_498115
Motivator

How can we create a role for group of users ..? can you pls tell wat options i have to give in the role to restrict users to MYAPP ..

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...