Splunk Search

Limit an Apps Search Context

rdevine
Path Finder

I'm hoping to create apps for each of our departments that only allow them to search specific data from splunk. This Document covers how to limit users to a specific app or apps, however, in that app how do I limit what data they can search on. We dump all of our event log data to the same index, so in a perfect world, these would not be per-index limits, but rather masked search terms that prefix their searches.

0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

In that case you'd probably want to create several roles for the various departments. When you create a role you can have search limitations prepended for that role. Look in Manager > Access Controls > Roles. You can then assign users to that role.

View solution in original post

sdaniels
Splunk Employee
Splunk Employee

In that case you'd probably want to create several roles for the various departments. When you create a role you can have search limitations prepended for that role. Look in Manager > Access Controls > Roles. You can then assign users to that role.

rakesh007
New Member

Can you please tell me how to access the Manager > access controls > roles?

0 Karma

rdevine
Path Finder

This is exactly what i was looking for. Thank you.

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...