Security

Remove search ability users

mmoermans
Path Finder

Hi there,

I'm trying to set up a monitor/manager account which only has access to dashboards but cannot search through indexes himself.
Where do you set this permission?

0 Karma

inventsekar
Ultra Champion

After creating user, create a role for this user and assign this role only the read permission for dashboard.

Please, create a role for this user before create this user, thus you can assign this role for this user and assign only the read permission for this user role.

if you don't want that user cannot search, either:

under Indexes, don't select no index, leave input Selected search indexes blank and save. Thus, your user cannot run search.

create an app for this dashboard and in the default nav four your app, only call the dashboards which user will see like this for example:

After do this edit your user and give it this app context by default

https://answers.splunk.com/answers/224735/how-to-restrict-a-users-role-to-only-view-a-dashbo.html

0 Karma

inventsekar
Ultra Champion

edit - not sure if this can be done.. lets wait for others answers.

not sure of this one, but please check this Capability
"search" --- Run searches,
"srchIndexesAllowed"

but still, we can add or remove the search capability, but there is no separate capability for granting the dashboard. i think its not possible. lets wait for others answers.

"search" --- Run searches,
"srchIndexesAllowed" - User is allowed to search indexes.
https://docs.splunk.com/Documentation/Splunk/6.6.2/Security/Rolesandcapabilities

0 Karma

mmoermans
Path Finder

srchIndexesAllowed only lets you definine which indexes can be searched.
If srchIndexesAllowed is empty then no results are found by Monitor user (in dashboards too).

[role_monitor]
cumulativeRTSrchJobsQuota = 0
cumulativeSrchJobsQuota = 0
importRoles = user_no_index
srchIndexesAllowed = network
srchIndexesDefault = network
srchMaxTime = 0

0 Karma

inventsekar
Ultra Champion

oops, my mistake. when i read the question, this issue came to my mind, but then missed it.

please check this Capability
"search" --- Run searches.

but still, we can add or remove the search capability, but there is no separate capability for granting the dashboard. i think its not possible. lets wait for others answers.

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

March Community Office Hours Security Series Uncovered!

Hello Splunk Community! In March, Splunk Community Office Hours spotlighted our fabulous Splunk Threat ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars in April. This post ...