Splunk Search

I want to provide read permission only one app not to all apps to a particular role

bapun18
Communicator

I want to provide read permission for only one app not all apps to a particular role and in my environment under apps permissions, I can see everyone(all roles) have read access. I don't want to make changes to all apps permission but wanted to manage if I can configure in one role or one app permissions so that all users under that role should only have read permission to one app and he won't be able to see other apps.

Labels (1)
Tags (3)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

i don’t know any easy way to do this like “allow all other roles than this”. Splunk’s way is allow for named roles or to all. This has done via *.meta files https://docs.splunk.com/Documentation/Splunk/8.2.4/Admin/Defaultmetaconf.  Basically you could do this by naming all other roles on all others apps meta files, but this is not a practical solution.

r. Ismo

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...