Splunk Search

How to filter fields for specific user from a index?

happylearning
Loves-to-Learn

let's say i have 1 index and we have multiple users, i want to assign a role so that user A can only view 5 interesting fields from 50 interesting fields. 

 

 

Labels (1)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try creating a new (summary) index with just the five fields in for each event in the main index as assign it to the restricted role.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @happylearning,

it isn't possible because in Splunk information access is managed at index level, so it isn't possible to create a role that can view only a part of information.

You can solve your requirement in two ways:

Create a dashboard for each role that visualize only the requested fields blocking the access to full events.

Copy the information in dedicated summary indexes containing only the information for one role.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...