Security

Is there a way to set new users to a probationary period to limit their permissions?

paimonsoror
Builder

I was wondering if there was a way to set new users in Splunk to a probationary period; where they are only allowed the ability to log in and run existing reports, but not run searches until an administrator 'unlocks' their account?

All of our Splunk access is controlled through LDAP groups, however we are finding many teams in our organization adding users to these groups without any training. I would like to capture these users and make sure that they take all of the required training before I fully allow them access to Splunk.

Does anyone have suggestions? Thanks!!

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi paimonsoror,
The only way to reach your needs is to configure a very limited role and use this role for the probationary period.
[Settings -- Access Controls -- Roles]

Bye.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi paimonsoror,
The only way to reach your needs is to configure a very limited role and use this role for the probationary period.
[Settings -- Access Controls -- Roles]

Bye.
Giuseppe

0 Karma

paimonsoror
Builder

Hi Giuseppe;

Thanks for the quick response. I am not too sure that this will work. So each "group" that has access to splunk has two splunk global groups, G_SPLK_GROUPNAME_USR and G_SPLK_GROUPNAME_PWR. I'm finding that a lot of teams are sneaking their 'default organization roles' to include BOTH(!!!!) of these in their defaults.

This means that whoever joins that team, automatically gets assigned these roles.

Sounds like Splunk might not have something to satisfy this, and I will have to fight the hard fight to make sure teams aren't doing this 🙂

Thanks for the help

0 Karma

ddrillic
Ultra Champion

Crazy - the access to power should be administered very carefully ; -)

paimonsoror
Builder

I agree. I couldn't believe it until i saw it for myself.

0 Karma

ddrillic
Ultra Champion

We all face this exact same issue - it comes with success ...

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...