Splunk Search

How to create restricted user role.

manivannan
New Member

Hi,I am new to splunk. I want to create a restricted user role who can just see the dashboards. he cant do search and view log information. Please help how can i achieve this.

Thanks in advance.

Tags (1)
0 Karma

Drainy
Champion

I have added a good link on it below.

But basically you just need to go to Manager in the top right; Select Access Controls in the User box down in the bottom right; Give the role and name and select the App with the dashboards you want to use; (a sidenote, an App is more like a workspace so you want to put all the dashboards per specific user / usergroup into a single app to restrict access); You can then select different capabilities or none depending on what you want the user to be able to do.

You are best building a dashboard without any search control and only access to the one App which contains these dashboards to restrict a user. Base the role on the User role or you may encounter some problems and bare in mind that they require some search capabilities to access some dashboards as a dashboard is essentially a collection of searches, if you restrict this then they won't be able to view a great deal on the dashboard.

See the following links for more detail;

User Roles:
http://docs.splunk.com/Documentation/Splunk/4.2.3/admin/Addandeditroles

Apps (Dashboards): http://docs.splunk.com/Documentation/Splunk/latest/User/SplunkApps

Drainy
Champion

Thats alright 🙂 Feel free to click the tick under the 0 and arrows to accept my answer if it works for you!

0 Karma

manivannan
New Member

Thanks you.. let me try your solution

0 Karma
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...