Security

Role: Limit access to one host of one index

chrisitanmoleck
Path Finder

Hello,

we are using Splunk v8.1.1

I have one user with multiple roles, so he can access multiple indexes and hosts.

The user need additionally access to one host in a multi-host index.

- role1 -> index1 -> all hosts
- role2 -> index2 -> all hosts
- role3 -> index3 -> one host (foo) of many

So I created a new role3 for index3 and a search filter for the host -> (host::foo)

Owning the three roles the user has only access to the host foo.

 

How can I limit the access to one host in a multi-host index without affect other roles?

 

Best Regards

Christian

 

 

 

Labels (1)
0 Karma

shangshin
Builder

good question

0 Karma
Get Updates on the Splunk Community!

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...

4 Ways the Splunk Community Helps You Prepare for .conf25

.conf25 is right around the corner, and whether you’re a first-time attendee or a seasoned Splunker, the ...