Deployment Architecture

Permission Distributed Search

dalie
Explorer

Hello,

Architecture:
I have a distributed Seach (not in Cluster)
1 Search head and 1 Indexer.

Every logs are stored on the indexer and with the search head user can search ....

Problem:
The problem is ... that I can allow a specific index per roles only on the indexer.
But user don't have an access to the indexer, they search via the GUI of the Search Head.

On the Search Head, I don't see the index create on the indexer, so the user have an access on every index
Is that possible to limit the access the search head ?

Thanks in advance

Tags (1)
0 Karma
1 Solution

adonio
Ultra Champion

place the indexes.conf on the search head as well
you are doing great by blocking the UI on the indexer

View solution in original post

0 Karma

adonio
Ultra Champion

place the indexes.conf on the search head as well
you are doing great by blocking the UI on the indexer

0 Karma

dalie
Explorer

It works !
One more question, every time That I will create and index on the indexer , I have to create this to the search head too then ?

0 Karma

FrankVl
Ultra Champion

Yes, you would need to keep that configuration in sync.

Since you are not using clustering, in theory you could use a Deployment Server to centrally manage such configuration that needs to go to multiple systems. But setting that up just for this 1 config file might be a bit overkill.

dalie
Explorer

Ok thanks I will try to do this 🙂

0 Karma

adonio
Ultra Champion

@dalie, if it works for you, kindly accept the answer and up-vote helpful comments
cheers

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...