Splunk Enterprise

How prevent to see "Apps" to user in splunk enterprise 9.0.2?

nikhilmfwd
Path Finder

Hello team,

Please help me out for this, i made one view-only role & attached to user. My requirement is when that user will open splunk that he can see only search & reporting not apps or "Apps" icon.

How prevent to see "Apps" to user in splunk enterprise 9.0.2?

 

Screenshot 2023-05-09 at 3.23.32 PM.png

Labels (1)
0 Karma
1 Solution

nikhilmfwd
Path Finder

Hello richgalloway,

Thanks for revert, my requirement is that "client should not be able to view which apps are configures in splunk". So can we disable that for them for that particular user or role?

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The first step is to assign a default app to the new view-only role.  That will ensure the user goes directly to that app right after login.

The second step is to change all other apps so the view-only role cannot access them.  For each app in the Manage Apps page, go to Permissions and choose the roles that are allowed access to the app.  Whenever a new role is created, repeat this process.

---
If this reply helps you, Karma would be appreciated.

nikhilmfwd
Path Finder

Hello richgalloway,

Thanks for revert, my requirement is that "client should not be able to view which apps are configures in splunk". So can we disable that for them for that particular user or role?

0 Karma

enzomialich
Path Finder

Just don't assign app permissions for the roles you don't want to interact with the app. If they don't have write or read permissions they won't see the app (expecting that the role doenst contain any admin rights).

 

You could also see the discussion: https://community.splunk.com/t5/Security/How-do-I-restrict-which-apps-are-visible-to-a-specific-AD-g...

nikhilmfwd
Path Finder

thanks enzomialich.. Its works for me.

0 Karma
Get Updates on the Splunk Community!

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...