Splunk Search

How to disable search in a specified index for certain groups of users?

Fleshwriter
Explorer

Hello.

I have a simple question:

I would like to have a specified index with sensitive data in it, however, I don't want every user to have access to it - only a few. How can I do it?

Do I create a custom users group?

Bests,
- F.

0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

You control access to indexes based upon roles.

So you create a new role group, and add the access to the index to the role group. Then you add the users to the role group.

http://docs.splunk.com/Documentation/Splunk/6.4.0/Security/Aboutusersandroles

View solution in original post

jkat54
SplunkTrust
SplunkTrust

You control access to indexes based upon roles.

So you create a new role group, and add the access to the index to the role group. Then you add the users to the role group.

http://docs.splunk.com/Documentation/Splunk/6.4.0/Security/Aboutusersandroles

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...