Security

Is it possible to restrict the capability "indexes_edit " to specific indexes?

jbrocks
Communicator

Title says it all.

We want to expand the "user" Role to create scheduled Reports (schedule_search) and write them to summary index, for which a user capability "indexes_edit". Otherwise, he will not be able to choose an index to write when editing the report.

Is it possible to restrict the "indexes_edit" capability to only write to a specific index and not to all indexes per default? I tried to restrict it by the "srchIndexesAllowed" but this does not have any effect.

0 Karma
1 Solution

prakash007
Builder

I don't think you can do that and it's not a good idea, indexes_edit would allow user to have access to all indexes when they navigate through settings--->data(indexes). That should be a admin-role capability....
Even if you create a new role with indexes_edit and restrict to specific index, they get access to all indexes...

It's a known issue in 7.2.1..
http://docs.splunk.com/Documentation/Splunk/7.2.1/ReleaseNotes/KnownIssues#Splunk_Web_and_interface_...
http://docs.splunk.com/Documentation/Splunk/7.2.1/Security/Rolesandcapabilities#List_of_capabilities

View solution in original post

0 Karma

prakash007
Builder

I don't think you can do that and it's not a good idea, indexes_edit would allow user to have access to all indexes when they navigate through settings--->data(indexes). That should be a admin-role capability....
Even if you create a new role with indexes_edit and restrict to specific index, they get access to all indexes...

It's a known issue in 7.2.1..
http://docs.splunk.com/Documentation/Splunk/7.2.1/ReleaseNotes/KnownIssues#Splunk_Web_and_interface_...
http://docs.splunk.com/Documentation/Splunk/7.2.1/Security/Rolesandcapabilities#List_of_capabilities

0 Karma
Get Updates on the Splunk Community!

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...