Security

Remove search ability users

mmoermans
Path Finder

Hi there,

I'm trying to set up a monitor/manager account which only has access to dashboards but cannot search through indexes himself.
Where do you set this permission?

0 Karma

inventsekar
SplunkTrust
SplunkTrust

After creating user, create a role for this user and assign this role only the read permission for dashboard.

Please, create a role for this user before create this user, thus you can assign this role for this user and assign only the read permission for this user role.

if you don't want that user cannot search, either:

under Indexes, don't select no index, leave input Selected search indexes blank and save. Thus, your user cannot run search.

create an app for this dashboard and in the default nav four your app, only call the dashboards which user will see like this for example:

After do this edit your user and give it this app context by default

https://answers.splunk.com/answers/224735/how-to-restrict-a-users-role-to-only-view-a-dashbo.html

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

inventsekar
SplunkTrust
SplunkTrust

edit - not sure if this can be done.. lets wait for others answers.

not sure of this one, but please check this Capability
"search" --- Run searches,
"srchIndexesAllowed"

but still, we can add or remove the search capability, but there is no separate capability for granting the dashboard. i think its not possible. lets wait for others answers.

"search" --- Run searches,
"srchIndexesAllowed" - User is allowed to search indexes.
https://docs.splunk.com/Documentation/Splunk/6.6.2/Security/Rolesandcapabilities

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

mmoermans
Path Finder

srchIndexesAllowed only lets you definine which indexes can be searched.
If srchIndexesAllowed is empty then no results are found by Monitor user (in dashboards too).

[role_monitor]
cumulativeRTSrchJobsQuota = 0
cumulativeSrchJobsQuota = 0
importRoles = user_no_index
srchIndexesAllowed = network
srchIndexesDefault = network
srchMaxTime = 0

0 Karma

inventsekar
SplunkTrust
SplunkTrust

oops, my mistake. when i read the question, this issue came to my mind, but then missed it.

please check this Capability
"search" --- Run searches.

but still, we can add or remove the search capability, but there is no separate capability for granting the dashboard. i think its not possible. lets wait for others answers.

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...