Security

Keep one type of data separated and limit access

Mark_Barrett
Explorer

I'm interested in importing a data type which is limited-access information and not accessible to most System Admins in our environment. However, I'm not sure how to ensure that once it has been brought into Splunk, to keep it locked down so that only specified Splunk users would be able to view this data.
I'm guessing that this data could be placed into a separate index file, but beyond that I have no idea how to set up the access (or if that's even possible?) Would be interested in finding any solutions, including any kind of tutorial or best-practice document out there to explain how to do this.

Tags (1)
0 Karma
1 Solution

tskinnerivsec
Contributor

You definitely want to ingest that data into its own index, then you can limit the users who have rights to view that index. An index is the smallest unit that you can apply an ACL to. Are you using local splunk logins or are you using ldap authentication? Basically, you create roles within splunk and either map users to those roles within splunk or you can map ldap groups to those roles and control the group membership in a directory service like Microsoft Active Directory.

View solution in original post

tskinnerivsec
Contributor

You definitely want to ingest that data into its own index, then you can limit the users who have rights to view that index. An index is the smallest unit that you can apply an ACL to. Are you using local splunk logins or are you using ldap authentication? Basically, you create roles within splunk and either map users to those roles within splunk or you can map ldap groups to those roles and control the group membership in a directory service like Microsoft Active Directory.

Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...