Splunk Enterprise

Is there be a way to configure a specific index to be searchable for a specific srchTimeWin?

arielpconsolaci
Path Finder

Hi fellow Splunkers,

Good day.  Would there be a way to configure a specific index to be searchable for a specific srchTimeWin?

Say the example below.

Scenario:

Splunk User has a user role with a search time win of 1 yr for all non-internal indexes.

We wanted a specific index to be searchable for 2 years only for the same user (the rest by 1yr searchable).

 

Test already done:

Create a new role and assign to a test user (with the user role) with the new role being searchable to the index of concern with srchTimeWin of 2years. However, all indexes were made searchable to 2 yrs as a result.


Thanks in advance.

Kind Regards,

Ariel

Labels (1)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

You can restrict a user to have additional limitations to his/her search.

https://docs.splunk.com/Documentation/Splunk/8.2.4/Security/Addandeditroles#Specify_default_app_and_...

But as far as I remember it's configured on a per-user basis, you can't set it to differentiate between  indexes.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...