Splunk Enterprise Security

In Splunk Enterprise Security, how do you create a user role with ready-only access?

sesharao92
Explorer

Is there any way to create a user role with read-only access to a specific set of indexes?

0 Karma

mayurr98
Super Champion

Have a look at this, might be useful to you:
https://answers.splunk.com/answers/10582/permissions-on-indexes-and-sourcetypes.html

let me know if this helps!

0 Karma

bangalorep
Communicator

You can create a role with only read access. You can go to settings >> access control >> roles
You can know more from the following link
https://docs.splunk.com/Documentation/Splunk/7.2.3/Admin/Aboutusersandroles

0 Karma

ddrillic
Ultra Champion

Interesting thing as Splunk roles are designed for read access, not for write access and each role has read access to a set of indexes.

If we look at About users and roles

It defines the user role as -

-- this role can create and edit its own saved searches, run searches, edit its own preferences, create and edit event types, and other similar tasks.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...