Security

Keep one type of data separated and limit access

Mark_Barrett
Explorer

I'm interested in importing a data type which is limited-access information and not accessible to most System Admins in our environment. However, I'm not sure how to ensure that once it has been brought into Splunk, to keep it locked down so that only specified Splunk users would be able to view this data.
I'm guessing that this data could be placed into a separate index file, but beyond that I have no idea how to set up the access (or if that's even possible?) Would be interested in finding any solutions, including any kind of tutorial or best-practice document out there to explain how to do this.

Tags (1)
0 Karma
1 Solution

tskinnerivsec
Contributor

You definitely want to ingest that data into its own index, then you can limit the users who have rights to view that index. An index is the smallest unit that you can apply an ACL to. Are you using local splunk logins or are you using ldap authentication? Basically, you create roles within splunk and either map users to those roles within splunk or you can map ldap groups to those roles and control the group membership in a directory service like Microsoft Active Directory.

View solution in original post

tskinnerivsec
Contributor

You definitely want to ingest that data into its own index, then you can limit the users who have rights to view that index. An index is the smallest unit that you can apply an ACL to. Are you using local splunk logins or are you using ldap authentication? Basically, you create roles within splunk and either map users to those roles within splunk or you can map ldap groups to those roles and control the group membership in a directory service like Microsoft Active Directory.

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...