Splunk Enterprise Security

In Splunk Enterprise Security, how do you create a user role with ready-only access?

sesharao92
Explorer

Is there any way to create a user role with read-only access to a specific set of indexes?

0 Karma

mayurr98
Super Champion

Have a look at this, might be useful to you:
https://answers.splunk.com/answers/10582/permissions-on-indexes-and-sourcetypes.html

let me know if this helps!

0 Karma

bangalorep
Communicator

You can create a role with only read access. You can go to settings >> access control >> roles
You can know more from the following link
https://docs.splunk.com/Documentation/Splunk/7.2.3/Admin/Aboutusersandroles

0 Karma

ddrillic
Ultra Champion

Interesting thing as Splunk roles are designed for read access, not for write access and each role has read access to a set of indexes.

If we look at About users and roles

It defines the user role as -

-- this role can create and edit its own saved searches, run searches, edit its own preferences, create and edit event types, and other similar tasks.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...