Our primary interest would be in allowing ad hoc searching of event data that is generated by Entuity Eye of the Storm (EYE). This is a rich data source containing events relating to many parts of a monitored network. Within EYE, users are members of one or more user groups and these user groups have permission settings that determine which groups of managed devices the users have access to. Users can therefore have overlapping access to details of some devices but details of other devices may be denied to them but not others. The integration to Splunk would ideally preserve the user permissions so that one common user login would cause the appropriate access rights to be granted. This would avoid any need to independently manage access rights on both products.
... View more