Security

Permissions to view knowledge objects but restrict search

Tim_1
Path Finder

Hi all,

Using Splunk enterprise 6.4.2, is it possible to allow users to view a dashboard that runs some savedsearches and also loads results from a savedsearch, but also restrict them from being able to run/write their own search queries.

If it is possible, what capabilities allow for this.

Thanks

0 Karma

nileena
Path Finder

I would suggesting hiding the search view, instead of removing search capability.
Go to Settings>User interface>Views.

Here, "search" is a view and you can change the permissions of this view and remove access to certain roles.

This way, the searches on dashboards and reports continue to run for the users belonging to these roles, but they wouldn't be able to access the search page to run ad hoc searches.

somesoni2
Revered Legend

Search capability is required for running dashboard searches and saved searches, so users will need search capability, allowing them to run adhoc searches.

0 Karma

Tim_1
Path Finder

@somesoni2, thanks, would it be possible to hide the search view from specific users then?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...