Security

Keep one type of data separated and limit access

Mark_Barrett
Explorer

I'm interested in importing a data type which is limited-access information and not accessible to most System Admins in our environment. However, I'm not sure how to ensure that once it has been brought into Splunk, to keep it locked down so that only specified Splunk users would be able to view this data.
I'm guessing that this data could be placed into a separate index file, but beyond that I have no idea how to set up the access (or if that's even possible?) Would be interested in finding any solutions, including any kind of tutorial or best-practice document out there to explain how to do this.

Tags (1)
0 Karma
1 Solution

tskinnerivsec
Contributor

You definitely want to ingest that data into its own index, then you can limit the users who have rights to view that index. An index is the smallest unit that you can apply an ACL to. Are you using local splunk logins or are you using ldap authentication? Basically, you create roles within splunk and either map users to those roles within splunk or you can map ldap groups to those roles and control the group membership in a directory service like Microsoft Active Directory.

View solution in original post

tskinnerivsec
Contributor

You definitely want to ingest that data into its own index, then you can limit the users who have rights to view that index. An index is the smallest unit that you can apply an ACL to. Are you using local splunk logins or are you using ldap authentication? Basically, you create roles within splunk and either map users to those roles within splunk or you can map ldap groups to those roles and control the group membership in a directory service like Microsoft Active Directory.

Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...