Security

Is it necessary to create indices, both on Search Head and Indexer?

davidcruz
Explorer

Hello guys,
After creating my indices in the Indexer and configure it as a search peer of my Search Head, I was able to search through every index that I've created in the Indexer.
BUUUT, when defining a role in the Search Head, I can't limit those indices because the index list only shows the Search Head indices.... Is there any way to resolve this, without duplicating these indices on the Search Head?
Thanks in advance 🙂

0 Karma

woodcock
Esteemed Legend

Yes, if you would like to use the user/role settings for index values AND like to have the in-search helps know about and suggest index values, then you must define them on the Search Head, too.

0 Karma

somesoni2
Revered Legend

If you want to edit role's index restriction from Splunk Web UI, you'd need those indexes to be created in Search Heads as well. Alternative to this would be setup role using configuration files on Search Head, where you can just mention the name of the indexes that are available in Indexers, without having them created in SH. See this:
http://docs.splunk.com/Documentation/Splunk/7.0.3/Security/Addandeditroleswithauthorizeconf

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...