Splunk Search

How do I add a Role Restriction Search Filter on a field available in only one index?

djacquens
Path Finder

Hi, 😉

I need to add a Role Restriction Search filter on a field which is only available in one index.
My problem is that I am not sure the proper way to force this restriction on only this index?

If I add a restriction like this

 

 

"field_name"="field_value"

 

it works fine for the index containing the value but the others indexes return nothing.

 

If I add a restriction like this:

 

((NOT "field_name"=* ) OR ( "field_name"="field_value"))

 

the result seems false.

Do you have an idea of the correct field to restrict this field?

Thanks, 😊

Regards,

David

 

0 Karma
1 Solution

yuanliu
SplunkTrust
SplunkTrust

I would just go with = as it works.

View solution in original post

0 Karma

yuanliu
SplunkTrust
SplunkTrust

I assume that the intention is to allow search in that index where field_name exists only when field_name==field_value but allow all searches when searching other indices?  If this is correct, how about

(index::that_index AND field_name::field_value) OR index!=that_index
0 Karma

djacquens
Path Finder

Thank you very much @yuanliu !

The SPL you gave me works only for me if I replace the :: by =.

(index=that_index AND field_name=field_value) OR index!=that_index


I understand this is not recommended but I don't understand how to fix it?


Thank you again,

 

David

0 Karma

yuanliu
SplunkTrust
SplunkTrust

I would just go with = as it works.

0 Karma

djacquens
Path Finder

Thank you very much @yuanliu  !!

 

Have a great day! 😉

David

0 Karma
Get Updates on the Splunk Community!

Now Playing: Splunk Education Summer Learning Premieres

It’s premiere season, and Splunk Education is rolling out new releases you won’t want to miss. Whether you’re ...

The Visibility Gap: Hybrid Networks and IT Services

The most forward thinking enterprises among us see their network as much more than infrastructure – it's their ...

Get Operational Insights Quickly with Natural Language on the Splunk Platform

In today’s fast-paced digital world, turning data into actionable insights is essential for success. With ...