Security

How to restrict users access to real time data and searches?

sravankaripe
Communicator

i want to restrict all users access to real time data and real time searches. how can i do this?

0 Karma
1 Solution

sravankaripe
Communicator

i want to re-stick all users except admin to access real time data and real time searches

0 Karma

sravankaripe
Communicator

Thanks its working

0 Karma

somesoni2
Revered Legend

Go through the instruction on section "Disable real-time search for a user or role" on the same page. Basically remove the capability rtsearch and schedule_rtsearch for the all roles except admin role. Do do this from backend, update the authorize.conf file.

direct link:
https://docs.splunk.com/Documentation/Splunk/6.5.0/Search/Restrictrealtimesearch#Disable_real-time_s...

0 Karma

sravankaripe
Communicator

can we do it from back end ?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...