Security

Is there a way to set new users to a probationary period to limit their permissions?

paimonsoror
Builder

I was wondering if there was a way to set new users in Splunk to a probationary period; where they are only allowed the ability to log in and run existing reports, but not run searches until an administrator 'unlocks' their account?

All of our Splunk access is controlled through LDAP groups, however we are finding many teams in our organization adding users to these groups without any training. I would like to capture these users and make sure that they take all of the required training before I fully allow them access to Splunk.

Does anyone have suggestions? Thanks!!

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi paimonsoror,
The only way to reach your needs is to configure a very limited role and use this role for the probationary period.
[Settings -- Access Controls -- Roles]

Bye.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi paimonsoror,
The only way to reach your needs is to configure a very limited role and use this role for the probationary period.
[Settings -- Access Controls -- Roles]

Bye.
Giuseppe

0 Karma

paimonsoror
Builder

Hi Giuseppe;

Thanks for the quick response. I am not too sure that this will work. So each "group" that has access to splunk has two splunk global groups, G_SPLK_GROUPNAME_USR and G_SPLK_GROUPNAME_PWR. I'm finding that a lot of teams are sneaking their 'default organization roles' to include BOTH(!!!!) of these in their defaults.

This means that whoever joins that team, automatically gets assigned these roles.

Sounds like Splunk might not have something to satisfy this, and I will have to fight the hard fight to make sure teams aren't doing this 🙂

Thanks for the help

0 Karma

ddrillic
Ultra Champion

Crazy - the access to power should be administered very carefully ; -)

paimonsoror
Builder

I agree. I couldn't believe it until i saw it for myself.

0 Karma

ddrillic
Ultra Champion

We all face this exact same issue - it comes with success ...

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...