Security

How do I prevent some users from running the collect command?

ben363
Path Finder

I want to be able to prevent some users from using the collect command. How to do that? Is there a capability that controls whether or not a user has permission to run collect?

1 Solution

inventsekar
SplunkTrust
SplunkTrust

ok, this is an old topic and it seems at that time of 2015 this feature was not there..

and now, authorize.conf gives a way to grant/remove this collect command from a user...

[capability::run_collect]
* Lets a user run the collect command.

http://docs.splunk.com/Documentation/Splunk/latest/Admin/Authorizeconf

(at this time of this writing the current splunk version is 7.1.2)

alanden_splunk
Splunk Employee
Splunk Employee

Verified that the collect command is connected to the authorize.conf permission [capability::indexes_edit]

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...