Splunk Search

Restrict access to views based on roles/users

manjunathmeti
Champion

I have 100 views and 5 different users/roles. Each user can access 20 views and this is based on prefix of those 20 views.
Example:
Type1_view1
Type1_view2
..
..
Type1_view20
Type2_view1
Type2_view2
..
..
Type2_view20
Type3_view1
..
Type5_view20

I edited local.meta as below but it is not working, each user is accessing all the 100 views. I need user 1 to access only Type1_* views, user2 to access only Type2_* views and so on.
[views/Type1_*]
access = read : [ user1 ], write : [ user1]

[views/Type2_*]
access = read : [ user2 ], write : [ user2]

Please suggest any solution you have, thanks.

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi manjunathmeti,
I don't think that you can use asterisk in local.meta, but you have a stanza for each Splunk Knowledge Object (views, fields, ...)

Before manually modify local.meta, try to modify, using web gui, one view for each user.
Then verify in local.meta if it's the same you manually did, and replicate for all objects.

Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...