Splunk Enterprise

How to hide index data from users searches

rayar
Contributor

Hi

I would like to make specific index data  invisible for all searches but not to actually delete it from the indexer and to keep all data integrations active 

is it possible  ? 

should I do with Role configuration  (Restrict search terms )   or there some other way   ?

If is am using role configuration , will the user see the data if he runs index=*   ?

thanks 

Labels (2)
0 Karma
1 Solution

scelikok
SplunkTrust
SplunkTrust

So, you can use Search Restriction like below;

index!=sensitive_index

It will filter all data from "sensitive_index" even on index=* searches.

If this reply helps you an upvote and "Accept as Solution" is appreciated.

View solution in original post

0 Karma

scelikok
SplunkTrust
SplunkTrust

So, you can use Search Restriction like below;

index!=sensitive_index

It will filter all data from "sensitive_index" even on index=* searches.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

rayar
Contributor

Hi

Currently we are using as below  (All non-internal indexes  marked )

we don't want t change it since the indexes list is dynamic 

rayar_0-1609150764261.png

what you would suggest   ?

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @rayar,

The best and safest way to restrict an index from user searches is specify searchable indexes from roles. You can find details in below document.

https://docs.splunk.com/Documentation/Splunk/8.1.1/Security/Addandeditroles#Specify_searchable_index... 

 

If this reply helps you an upvote is appreciated.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...