Security

Is it necessary to create indices, both on Search Head and Indexer?

davidcruz
Explorer

Hello guys,
After creating my indices in the Indexer and configure it as a search peer of my Search Head, I was able to search through every index that I've created in the Indexer.
BUUUT, when defining a role in the Search Head, I can't limit those indices because the index list only shows the Search Head indices.... Is there any way to resolve this, without duplicating these indices on the Search Head?
Thanks in advance 🙂

0 Karma

woodcock
Esteemed Legend

Yes, if you would like to use the user/role settings for index values AND like to have the in-search helps know about and suggest index values, then you must define them on the Search Head, too.

0 Karma

somesoni2
Revered Legend

If you want to edit role's index restriction from Splunk Web UI, you'd need those indexes to be created in Search Heads as well. Alternative to this would be setup role using configuration files on Search Head, where you can just mention the name of the indexes that are available in Indexers, without having them created in SH. See this:
http://docs.splunk.com/Documentation/Splunk/7.0.3/Security/Addandeditroleswithauthorizeconf

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...