Splunk Search

view default index

trojan_81
Path Finder

How can I view the default index of a user?

In other words, if user runs a search within splunk search app and does not specify an index, how do i view which index he will default at?

Labels (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust
Hi
In https://docs.splunk.com/Documentation/Splunk/7.3.3/Admin/Authorizeconf is role specific parameter: srchIndexesDefault which define this. If user have several roles or inherited roles then those all must combine.
Maybe this https://community.splunk.com/t5/Splunk-Search/is-there-a-way-to-search-who-has-access-to-an-index/m-... helps to figure out spl query to get this information.
r. Ismo

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Check the user's role.  That role may have one or more default indexes defined.  A search that doesn't specify an index will look in all of the defined default indexes.

---
If this reply helps you, Karma would be appreciated.
0 Karma

isoutamo
SplunkTrust
SplunkTrust
Hi
In https://docs.splunk.com/Documentation/Splunk/7.3.3/Admin/Authorizeconf is role specific parameter: srchIndexesDefault which define this. If user have several roles or inherited roles then those all must combine.
Maybe this https://community.splunk.com/t5/Splunk-Search/is-there-a-way-to-search-who-has-access-to-an-index/m-... helps to figure out spl query to get this information.
r. Ismo
0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...