Splunk Search

Restrict access to views based on roles/users

manjunathmeti
Champion

I have 100 views and 5 different users/roles. Each user can access 20 views and this is based on prefix of those 20 views.
Example:
Type1_view1
Type1_view2
..
..
Type1_view20
Type2_view1
Type2_view2
..
..
Type2_view20
Type3_view1
..
Type5_view20

I edited local.meta as below but it is not working, each user is accessing all the 100 views. I need user 1 to access only Type1_* views, user2 to access only Type2_* views and so on.
[views/Type1_*]
access = read : [ user1 ], write : [ user1]

[views/Type2_*]
access = read : [ user2 ], write : [ user2]

Please suggest any solution you have, thanks.

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi manjunathmeti,
I don't think that you can use asterisk in local.meta, but you have a stanza for each Splunk Knowledge Object (views, fields, ...)

Before manually modify local.meta, try to modify, using web gui, one view for each user.
Then verify in local.meta if it's the same you manually did, and replicate for all objects.

Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Bridging the Gap: Splunk Helps Students Move from Classroom to Career

The Splunk Community is a powerful network of users, educators, and organizations working together to tackle ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...