Security

Role: Limit access to one host of one index

chrisitanmoleck
Path Finder

Hello,

we are using Splunk v8.1.1

I have one user with multiple roles, so he can access multiple indexes and hosts.

The user need additionally access to one host in a multi-host index.

- role1 -> index1 -> all hosts
- role2 -> index2 -> all hosts
- role3 -> index3 -> one host (foo) of many

So I created a new role3 for index3 and a search filter for the host -> (host::foo)

Owning the three roles the user has only access to the host foo.

 

How can I limit the access to one host in a multi-host index without affect other roles?

 

Best Regards

Christian

 

 

 

Labels (1)
0 Karma

shangshin
Builder

good question

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...