Splunk Search

Is it possible restrict a user search by data values?

hketer
Path Finder

Hey!

For example, if I have events contain different countries.
Is it possible to restrict users by specific values?
So they'll be able to search only specific country or more.

I know the is option to restrict by index, its not what I want.
Thank you!!

Tags (1)
0 Karma
1 Solution

mayurr98
Super Champion

I do think if you can do it by a user, but we can definitely do it by Role and then you can assign the role to that specific user.

alt text

Go to Setting>>Access controls>>Roles
you can use specific search values or field value

for example,
1) "Canada" OR "Nepal" OR "America" OR ..

2) "Country=Canada" OR "Country=Nepal" OR "Country=America" OR ..

For more info read,
https://docs.splunk.com/Documentation/Splunk/7.2.5/Security/Addandeditroleswithauthorizeconf#Search_...

View solution in original post

0 Karma

vishaltaneja070
Motivator

Hello @hketer

If there is field called countries, then you can restrict by search term in roles definition like County = "Australia".

0 Karma

mayurr98
Super Champion

I do think if you can do it by a user, but we can definitely do it by Role and then you can assign the role to that specific user.

alt text

Go to Setting>>Access controls>>Roles
you can use specific search values or field value

for example,
1) "Canada" OR "Nepal" OR "America" OR ..

2) "Country=Canada" OR "Country=Nepal" OR "Country=America" OR ..

For more info read,
https://docs.splunk.com/Documentation/Splunk/7.2.5/Security/Addandeditroleswithauthorizeconf#Search_...

0 Karma
Get Updates on the Splunk Community!

Exciting News: The AppDynamics Community Joins Splunk!

Hello Splunkers,   I’d like to introduce myself—I’m Ryan, the former AppDynamics Community Manager, and I’m ...

The All New Performance Insights for Splunk

Splunk gives you amazing tools to analyze system data and make business-critical decisions, react to issues, ...

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...