Splunk Search

How to disable search in a specified index for certain groups of users?

Fleshwriter
Explorer

Hello.

I have a simple question:

I would like to have a specified index with sensitive data in it, however, I don't want every user to have access to it - only a few. How can I do it?

Do I create a custom users group?

Bests,
- F.

0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

You control access to indexes based upon roles.

So you create a new role group, and add the access to the index to the role group. Then you add the users to the role group.

http://docs.splunk.com/Documentation/Splunk/6.4.0/Security/Aboutusersandroles

View solution in original post

jkat54
SplunkTrust
SplunkTrust

You control access to indexes based upon roles.

So you create a new role group, and add the access to the index to the role group. Then you add the users to the role group.

http://docs.splunk.com/Documentation/Splunk/6.4.0/Security/Aboutusersandroles

Get Updates on the Splunk Community!

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...