Splunk Search

How to create restricted user role.

manivannan
New Member

Hi,I am new to splunk. I want to create a restricted user role who can just see the dashboards. he cant do search and view log information. Please help how can i achieve this.

Thanks in advance.

Tags (1)
0 Karma

Drainy
Champion

I have added a good link on it below.

But basically you just need to go to Manager in the top right; Select Access Controls in the User box down in the bottom right; Give the role and name and select the App with the dashboards you want to use; (a sidenote, an App is more like a workspace so you want to put all the dashboards per specific user / usergroup into a single app to restrict access); You can then select different capabilities or none depending on what you want the user to be able to do.

You are best building a dashboard without any search control and only access to the one App which contains these dashboards to restrict a user. Base the role on the User role or you may encounter some problems and bare in mind that they require some search capabilities to access some dashboards as a dashboard is essentially a collection of searches, if you restrict this then they won't be able to view a great deal on the dashboard.

See the following links for more detail;

User Roles:
http://docs.splunk.com/Documentation/Splunk/4.2.3/admin/Addandeditroles

Apps (Dashboards): http://docs.splunk.com/Documentation/Splunk/latest/User/SplunkApps

Drainy
Champion

Thats alright 🙂 Feel free to click the tick under the 0 and arrows to accept my answer if it works for you!

0 Karma

manivannan
New Member

Thanks you.. let me try your solution

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...