Security

Are there any limitations to using Splunk Apps and roles for access management?

JChris_
Path Finder

Hello,

I'm a Splunk Cloud admin who has the following challenge: I want to segregate the access of multiple teams within the company so they can only R/W the reports, alerts, and dashboards that are owned by such teams. My idea is to create an app for each team. Let's use this team structure for example:

  • SOC Team
  • AppSec Team
  • R&D Team

 

First, I would create the following roles:

  • SOC
  • AppSec
  • R&D

Second, I would create the following apps and attach the roles like this:

  • SOC (SOC Role has R/W access, others have NO access)
  • AppSec (AppSec Role has R/W access, others have READ only)
  • R&D Role (R&D Role has R/W access, others have READ only)

 

With this implemented, each team will be able to creates alerts/dashboards/etc with the permission "shared in app" and this won't affect the other teams.

 

Is there any issue/limitation with this approach? I did not spot any issue.

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

That approach seems fine.  Remember that you are only controlling access to the knowledge objects (KOs) in those apps.  Any data used by those KOs may still be accessible to other roles.

---
If this reply helps you, Karma would be appreciated.
0 Karma

JChris_
Path Finder

Oh yes, I know the indexes will continue to be seen by everyone by default. The is a whole different issue which is way harder to deal with xD

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...