Security

How to use lookup field in roles

yaarek
New Member

Hi,

I'm trying to add splunk access to a user.

I have a search which creates lookup with hosts names. It is created based on IP from _internal logs - I have a list of IP ranges.

Now I wanted to created a role, with restrictions to hosts from lookup.

I've tried to create a event type, but I can't use pipes there, to read lookup.

I've also tried to use inputlookup command in role restrictions, but no luck.

 

Any Idea how to do it? Maybe other way, without lookup?

 

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Cultivate Your Career Growth with Fresh Splunk Training

Growth doesn’t just happen—it’s nurtured. Like tending a garden, developing your Splunk skills takes the right ...

Introducing a Smarter Way to Discover Apps on Splunkbase

We’re excited to announce the launch of a foundational enhancement to Splunkbase: App Tiering.  Because we’ve ...

How to Send Splunk Observability Alerts to Webex teams in Minutes

As a Developer Evangelist at Splunk, my team and I are constantly tinkering with technology to explore its ...