Security

How can I make sure a role setting takes precedence over other role settings?

twinspop
Influencer

I have a user that belongs to a few roles that use LDAP for auth. These roles have srchMaxTime set to 600. I need to cap the user at 300 seconds for srchMaxTime. I have set-up 2 roles named aaa_search_abuser and zzz_search_abuser with this setting, and assigned the user to those roles (in addition the the other roles he belongs to). However, the user still shows with a 600 srchMaxTime. It seems like the role engine is choosing the highest value, not any sort of order-based process.

How can I make sure a role setting takes precedence over other role settings?

thanks

0 Karma

jkat54
SplunkTrust
SplunkTrust

According to authorize.conf.spec srchMaxTime inherits the maximum from the other roles.

http://docs.splunk.com/Documentation/Splunk/6.5.1/admin/Authorizeconf

Looks like you need a role specifically for this user.

0 Karma

ddrillic
Ultra Champion
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...