Reporting

Splunk user unable to access datamodel data.

jayakumar19
Observer

Users are unable to access data from a dashboard. We are using a datamodel to create that dashboard. We have enable read access for this dashboard and datamodel but not to the raw data index. Please help me to provide data access for dashboard to user without giving access for that index (raw data).

Thanks in advance!!

Labels (1)
0 Karma

codebuilder
Influencer

Although there are some potential workarounds to the issue you describe, the short answer is that you cannot grant access to a datamodel without also granting access to the index. Datamodels are tied to indexes, therefore the searches are also tied to the indexes. This is especially true with accelerated datamodels. If a user attempts to pull search results from a datamodel that is either not accelerated, or the search is outside the range of acceleration, Splunk will default to a "normal" index search.

As I mentioned, there are some potential workarounds (and likely more options than I personally know), but the first solution that comes to mind is to create a scheduled search. Create the search, schedule it to run at a certain day/time, and use the results from this to populate your dashboard. In that scenario, the user does not need access to the index itself.

A better option, in my opinion, is to grant read only access to the index behind your dashboards, but disable access to the default search app. In that way, users will be able to see populated dashboards, but not be able to manipulate the URL in such a way that they can query the index directly.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...