I have a question about the port and indexes access. I want to konw if it is possible to control index or port access. For example, I want only the users with the admin role can access to the index "_test" that I have create, how can do it????
Login to your Splunk instance through a browser. Click on Manager > Access Controls > Roles > New, and you can create a role that limits access to indexes. You will find a list of all the available indexes, so you can pick what you want.