Splunk Search

Limit an Apps Search Context

rdevine
Path Finder

I'm hoping to create apps for each of our departments that only allow them to search specific data from splunk. This Document covers how to limit users to a specific app or apps, however, in that app how do I limit what data they can search on. We dump all of our event log data to the same index, so in a perfect world, these would not be per-index limits, but rather masked search terms that prefix their searches.

0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

In that case you'd probably want to create several roles for the various departments. When you create a role you can have search limitations prepended for that role. Look in Manager > Access Controls > Roles. You can then assign users to that role.

View solution in original post

sdaniels
Splunk Employee
Splunk Employee

In that case you'd probably want to create several roles for the various departments. When you create a role you can have search limitations prepended for that role. Look in Manager > Access Controls > Roles. You can then assign users to that role.

rakesh007
New Member

Can you please tell me how to access the Manager > access controls > roles?

0 Karma

rdevine
Path Finder

This is exactly what i was looking for. Thank you.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...