Security

How to restrict users access to real time data and searches?

sravankaripe
Communicator

i want to restrict all users access to real time data and real time searches. how can i do this?

0 Karma
1 Solution

sravankaripe
Communicator

i want to re-stick all users except admin to access real time data and real time searches

0 Karma

sravankaripe
Communicator

Thanks its working

0 Karma

somesoni2
SplunkTrust
SplunkTrust

Go through the instruction on section "Disable real-time search for a user or role" on the same page. Basically remove the capability rtsearch and schedule_rtsearch for the all roles except admin role. Do do this from backend, update the authorize.conf file.

direct link:
https://docs.splunk.com/Documentation/Splunk/6.5.0/Search/Restrictrealtimesearch#Disable_real-time_s...

0 Karma

sravankaripe
Communicator

can we do it from back end ?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...