Security

Splunk Dashboard to show fields based on the user role

Priya312
Explorer

Hi,

Currently I'm developing a html dashboard which every users can view it.
But in the drilldown of the dashboard, a set of fields will be displayed as table.
I want to show the value of particular field only to certain users and for other users the field should be hidden/shown without any values.

How can i achieve this in HTML dashboard?

Tags (2)
0 Karma

vasanthmss
Motivator

You can put your custom field filter into "search time restrictions" on the Roles. Go to Settings-> Access controls » Roles -> YOur Role for each user -> Search Restrictions -> Restrict search terms"

Or create some lookup with following details user roles and required fields. Use the lookup in youe search.

you can retrieve the logged in user details by using this query,

| rest /services/authentication/current-context splunk_server=local  | table username,realname,roles

Check this post http://answers.splunk.com/answers/28633/current-user-in-search.html

V
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...