I want to set up various user roles to users in my splunk instances. Like Users from Group A should only have access to index A and So on. I tried
1. creating a new role called UserGroupA and add the index A to the role and adding the inherited parent as user role.
2. Cloned user role and restrict the index to index A. but none of this worked for me.
Note: But if I restrict indexes to the role User without any additional roles added, then it's working. But my use case is to set up multiple roles based on index and allow users to access only the index results and dashboards.