Security

How to allow a Splunk user to access only part of an index?

msudhindra
Path Finder

Hello All,

We have a requirement, where a team wants to monitor system performance on some of their systems that report into Splunk.

I would like to provide them access to that data, but not let them see the performance metrics or stats from other systems that they do not control, or allow them to look at the security logs from that system.

In a situation like this, where all hosts of a particular OS (say Windows) log their data into a single index (index=windows), how can I allow this team to view only certain portions of the index that they are allowed access to ?

Thanks and Regards,
Madan Sudhindra

0 Karma

jhidalgo_splunk
Splunk Employee
Splunk Employee

You can move part of the original index data to a summary index with "collect" and assign permissions accordingly.

0 Karma

Jason
Motivator

Best practice is to split data into different indexes based on different access requirements or retention requirements that you may have. Then, assign the user's role access to only the index with the data required.

You can not split access in one index, aside from using search filters. These are not 100% secure however, and can reduce performance significantly, so are not recommended.

Another option to consider is to create that user their own app with their own set of dashboards and form searches, if simply removing the option to easily freeform search is a possibility.

ppablo
Retired

Hi @msudhindra

I've never had to do this myself, but from digging through documentation, you should be able to choose a particular index they can search and further filter access by adding search filters to their roles that pertain only to performance metrics data.
http://docs.splunk.com/Documentation/Splunk/6.2.1/Security/Addandeditroles#Search_filter_format

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...