Splunk Search

How to disable search in a specified index for certain groups of users?

Fleshwriter
Explorer

Hello.

I have a simple question:

I would like to have a specified index with sensitive data in it, however, I don't want every user to have access to it - only a few. How can I do it?

Do I create a custom users group?

Bests,
- F.

0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

You control access to indexes based upon roles.

So you create a new role group, and add the access to the index to the role group. Then you add the users to the role group.

http://docs.splunk.com/Documentation/Splunk/6.4.0/Security/Aboutusersandroles

View solution in original post

jkat54
SplunkTrust
SplunkTrust

You control access to indexes based upon roles.

So you create a new role group, and add the access to the index to the role group. Then you add the users to the role group.

http://docs.splunk.com/Documentation/Splunk/6.4.0/Security/Aboutusersandroles

Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...