Splunk Enterprise

Is there be a way to configure a specific index to be searchable for a specific srchTimeWin?

arielpconsolaci
Path Finder

Hi fellow Splunkers,

Good day.  Would there be a way to configure a specific index to be searchable for a specific srchTimeWin?

Say the example below.

Scenario:

Splunk User has a user role with a search time win of 1 yr for all non-internal indexes.

We wanted a specific index to be searchable for 2 years only for the same user (the rest by 1yr searchable).

 

Test already done:

Create a new role and assign to a test user (with the user role) with the new role being searchable to the index of concern with srchTimeWin of 2years. However, all indexes were made searchable to 2 yrs as a result.


Thanks in advance.

Kind Regards,

Ariel

Labels (1)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

You can restrict a user to have additional limitations to his/her search.

https://docs.splunk.com/Documentation/Splunk/8.2.4/Security/Addandeditroles#Specify_default_app_and_...

But as far as I remember it's configured on a per-user basis, you can't set it to differentiate between  indexes.

0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...