Splunk Search

Restrict access to views based on roles/users

manjunathmeti
Champion

I have 100 views and 5 different users/roles. Each user can access 20 views and this is based on prefix of those 20 views.
Example:
Type1_view1
Type1_view2
..
..
Type1_view20
Type2_view1
Type2_view2
..
..
Type2_view20
Type3_view1
..
Type5_view20

I edited local.meta as below but it is not working, each user is accessing all the 100 views. I need user 1 to access only Type1_* views, user2 to access only Type2_* views and so on.
[views/Type1_*]
access = read : [ user1 ], write : [ user1]

[views/Type2_*]
access = read : [ user2 ], write : [ user2]

Please suggest any solution you have, thanks.

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi manjunathmeti,
I don't think that you can use asterisk in local.meta, but you have a stanza for each Splunk Knowledge Object (views, fields, ...)

Before manually modify local.meta, try to modify, using web gui, one view for each user.
Then verify in local.meta if it's the same you manually did, and replicate for all objects.

Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...