Hi,
I want to restrict access to different teams based on hosts but don't want to do it by creating multiple indexes for this. The data would be present in one index and teams would be given access to this index, however they should be able to see only the data they own. Is there a way host-based restriction can be achieved?
Hi @AMAN0113 .. please check these pages:
https://docs.splunk.com/Documentation/Splunk/9.1.1/Security/limitfieldfiltering