Splunk Search
Highlighted

Limit Queries based on user accounts

Explorer

I would like to spearate general query utilization between various groups. Example: only allowing Scruirty personnel the ability to look at logs from specific security devices.

Is this possible?

0 Karma
Highlighted

Re: Limit Queries based on user accounts

Legend

Sure. You can do this by creating a role, say, "security_personnel", assigning search term restrictions to that role and then finally adding the users you want to that role. In the web UI under Manager >> Access controls >> Roles >> (your chosen role), there is a field called "Restrict search terms" that you can use to add whatever restrictions you want for that role. These search terms will be implicitly added to any search that users of this role issue.

More information on users and roles is available in the Admin manual here: http://www.splunk.com/base/Documentation/latest/Admin/Addusersandassignroles

Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.