Security

how to restrict users group to access particular index only

saifuddin9122
Path Finder

Hello

we have two indexes (A,B) and i have 3 different groups.
1. admin
2. US-East-users
3. US-central-users

our goal is admin group members should have access to both indexes and US-East-users should have access to index A only US-central-users should have access to index B.

even the user in any group other than admin searches for index=* , they should get data from only the index to which they have access.

how should i implement this? can any one help me in doing so?

Thanks in Advance.

Tags (2)
0 Karma
1 Solution

adonio
Ultra Champion

hello saifuddin9122,
navigate to settings -> access controls -> roles -> US-East-users -> scroll all the way down -> add index A to the bottom box (restricted indexes) -> click save -> repeat for other roles

alt text

View solution in original post

adonio
Ultra Champion

hello saifuddin9122,
navigate to settings -> access controls -> roles -> US-East-users -> scroll all the way down -> add index A to the bottom box (restricted indexes) -> click save -> repeat for other roles

alt text

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...