Splunk Search

Limit an Apps Search Context

rdevine
Path Finder

I'm hoping to create apps for each of our departments that only allow them to search specific data from splunk. This Document covers how to limit users to a specific app or apps, however, in that app how do I limit what data they can search on. We dump all of our event log data to the same index, so in a perfect world, these would not be per-index limits, but rather masked search terms that prefix their searches.

0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

In that case you'd probably want to create several roles for the various departments. When you create a role you can have search limitations prepended for that role. Look in Manager > Access Controls > Roles. You can then assign users to that role.

View solution in original post

sdaniels
Splunk Employee
Splunk Employee

In that case you'd probably want to create several roles for the various departments. When you create a role you can have search limitations prepended for that role. Look in Manager > Access Controls > Roles. You can then assign users to that role.

View solution in original post

rakesh007
New Member

Can you please tell me how to access the Manager > access controls > roles?

0 Karma

rdevine
Path Finder

This is exactly what i was looking for. Thank you.

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!