Splunk Search

Index Access

nikhilmehra79
Path Finder

Hi,

I want to give access to my splunk customers users acccess to only specific imndexes and not main indexes.

I also want to restrict that they search on that specific index and not main index, so if i created an index called si_test - the user by default should search in si_test and have access to this index data only - is that possible?

0 Karma
1 Solution

lguinn2
Legend

Absolutely!

This is set in the roles, under Access Controls. I recommend that you set up a new role and give it access to only the indexes that you want. Then assign the users to that role.

Do not use role inheritance unless you read the documentation and/or understand how access to indexes is inherited.

View solution in original post

0 Karma

lguinn2
Legend

Absolutely!

This is set in the roles, under Access Controls. I recommend that you set up a new role and give it access to only the indexes that you want. Then assign the users to that role.

Do not use role inheritance unless you read the documentation and/or understand how access to indexes is inherited.

0 Karma

nikhilmehra79
Path Finder

I actually tired that, my AD has a group called XYZ, it has 2 users.

I created a AD auth through splunk, user shows up and i assigned role to these users.

Role only give them priv to log in and search on index si_test and block index "main"

still when i log in as that user, i can search on events which are supposed to be main index, no idea why ?

I am at 6.0.3

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...