Avoid search filters. While they can be useful at times, more often they complicate matters. For instance, in your case the members of 6-8 AD groups (therefore, presumably, in 6-8 Splunk roles) will have 6-8 search filters combined with implicit AND operators to create a search that finds nothing. The only reliable way to control access to data is to put that data in an index with the proper RBAC settings. Rather than have a single summary index, it would be better to create a separate summary index for each group of users with unique access requirements.
... View more