Security

How to restrict users access to real time data and searches?

sravankaripe
Communicator

i want to restrict all users access to real time data and real time searches. how can i do this?

0 Karma
1 Solution

sravankaripe
Communicator

i want to re-stick all users except admin to access real time data and real time searches

0 Karma

sravankaripe
Communicator

Thanks its working

0 Karma

somesoni2
Revered Legend

Go through the instruction on section "Disable real-time search for a user or role" on the same page. Basically remove the capability rtsearch and schedule_rtsearch for the all roles except admin role. Do do this from backend, update the authorize.conf file.

direct link:
https://docs.splunk.com/Documentation/Splunk/6.5.0/Search/Restrictrealtimesearch#Disable_real-time_s...

0 Karma

sravankaripe
Communicator

can we do it from back end ?

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...