Hi @phpguy_80, in few words, Splunk don't permit to modify indexed data, so you have only to disable (or not enable) capabilities as knowledge objects creation or modify and log delete. So you could start to enable: change_own_password rtsearch (only if user must be enabled to Real Time Searches) search I don't know what your Apps contain, so e.g. if you have a dashboard that lists Deployment Clients using a REST command, you have to enable a specific feature as "rest_properties_get". As I said, remember to enable the correct Indexes. Ciao. Giuseppe
... View more