Security

Access Controls

sameer12sa
Engager

Hi

Can we have configure users according to the monitors defined at the Universal Forwarder?
We are trying to have a splunk server which monitors mail server and weblogic logs. I am trying to create users who can only access mail server logs and another group which can only access weblogic logs.

Is there any way to do that?

Thanks
Sameer

Tags (1)

dwaddle
SplunkTrust
SplunkTrust

The most robust approach is to put each different role's data into its own index. You'd have a "mail" index and a "weblogic" index, and each inputs.conf stanza would explicitly say index=<foo>. Then, you configure each role as to the index(es) it's allowed to use, and drop the users into the proper roles .... and Bob's your uncle.

lpolo
Motivator

You can do it by defining the roles of each set of users in Splunk. More information:

http://docs.splunk.com/Documentation/Splunk/4.3.1/Admin/Aboutusersandroles

Manager » Access controls

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Asynchronous Forwarding Explained

Splunk asynchronous forwarding is often misunderstood as simply setting autoLBVolume. That is not quite right. ...

55 Days to Go: Secure Your Seat at Splunk University in Denver

Your .conf26 Experience Starts Before Opening Keynote  If Denver is known for its mile-high elevation, Splunk ...

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...