Security

Keep one type of data separated and limit access

Mark_Barrett
Explorer

I'm interested in importing a data type which is limited-access information and not accessible to most System Admins in our environment. However, I'm not sure how to ensure that once it has been brought into Splunk, to keep it locked down so that only specified Splunk users would be able to view this data.
I'm guessing that this data could be placed into a separate index file, but beyond that I have no idea how to set up the access (or if that's even possible?) Would be interested in finding any solutions, including any kind of tutorial or best-practice document out there to explain how to do this.

Tags (1)
0 Karma
1 Solution

tskinnerivsec
Contributor

You definitely want to ingest that data into its own index, then you can limit the users who have rights to view that index. An index is the smallest unit that you can apply an ACL to. Are you using local splunk logins or are you using ldap authentication? Basically, you create roles within splunk and either map users to those roles within splunk or you can map ldap groups to those roles and control the group membership in a directory service like Microsoft Active Directory.

View solution in original post

tskinnerivsec
Contributor

You definitely want to ingest that data into its own index, then you can limit the users who have rights to view that index. An index is the smallest unit that you can apply an ACL to. Are you using local splunk logins or are you using ldap authentication? Basically, you create roles within splunk and either map users to those roles within splunk or you can map ldap groups to those roles and control the group membership in a directory service like Microsoft Active Directory.

Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...