Security

Authorize.conf filtering indexes

rmorlen
Splunk Employee
Splunk Employee

I would like to restrict some indexes from certain role. I can modify the srchFiler in authorize.conf to exclude 1 index but can't see to get it to work for multiple indexes.

srchFilter="index!=abc" works

srchFilter="index!=abc;index!=def" does not work.

Our users have access to all indexes (over 100). We only want to exclude some of the indexes.

Any help would be appreciated.

Tags (2)
0 Karma

somesoni2
Revered Legend

You can use filters like this (no need for semicolon separated values)

srchFilter = NOT (index=abc OR index=xyz)
0 Karma

somesoni2
Revered Legend

Could provide the DEBUG message from the Search Inspector ?
Also, since you're changing the conf file, you're doing refresh/restart of splunk after change right?

0 Karma

rmorlen
Splunk Employee
Splunk Employee

I tried this but it didn't seem to take effect. I could still search index=xyz.

srchFilter = NOT (index=abc OR index=xyz)
srchIndexesAllowed = ;_
srchIndexesDefault = *

0 Karma
Get Updates on the Splunk Community!

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...