Security

Are there any limitations to using Splunk Apps and roles for access management?

JChris_
Path Finder

Hello,

I'm a Splunk Cloud admin who has the following challenge: I want to segregate the access of multiple teams within the company so they can only R/W the reports, alerts, and dashboards that are owned by such teams. My idea is to create an app for each team. Let's use this team structure for example:

  • SOC Team
  • AppSec Team
  • R&D Team

 

First, I would create the following roles:

  • SOC
  • AppSec
  • R&D

Second, I would create the following apps and attach the roles like this:

  • SOC (SOC Role has R/W access, others have NO access)
  • AppSec (AppSec Role has R/W access, others have READ only)
  • R&D Role (R&D Role has R/W access, others have READ only)

 

With this implemented, each team will be able to creates alerts/dashboards/etc with the permission "shared in app" and this won't affect the other teams.

 

Is there any issue/limitation with this approach? I did not spot any issue.

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

That approach seems fine.  Remember that you are only controlling access to the knowledge objects (KOs) in those apps.  Any data used by those KOs may still be accessible to other roles.

---
If this reply helps you, Karma would be appreciated.
0 Karma

JChris_
Path Finder

Oh yes, I know the indexes will continue to be seen by everyone by default. The is a whole different issue which is way harder to deal with xD

0 Karma
Get Updates on the Splunk Community!

Changes to Splunk Instructor-Led Training Completion Criteria

We’re excited to share an update to our instructor-led training program that enhances the learning experience ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

❄️ Welcome the new year with our January lineup of Community Office Hours, Tech Talks, and Webinars! 🎉 ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...