Splunk Search

I want to provide read permission only one app not to all apps to a particular role

bapun18
Communicator

I want to provide read permission for only one app not all apps to a particular role and in my environment under apps permissions, I can see everyone(all roles) have read access. I don't want to make changes to all apps permission but wanted to manage if I can configure in one role or one app permissions so that all users under that role should only have read permission to one app and he won't be able to see other apps.

Labels (1)
Tags (3)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

i don’t know any easy way to do this like “allow all other roles than this”. Splunk’s way is allow for named roles or to all. This has done via *.meta files https://docs.splunk.com/Documentation/Splunk/8.2.4/Admin/Defaultmetaconf.  Basically you could do this by naming all other roles on all others apps meta files, but this is not a practical solution.

r. Ismo

Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...