All Apps and Add-ons

After data is indexed from two different hosts, is there a way to filter on two search heads so teams only see their respective host's data?

RomeoG
New Member

We have a single indexer aggregating logs from our different teams.... Server, virtualization, Network, etc..... Generally, our teams use different apps. Unfortunately, I have 2 virtualization teams, each with their own Search Head, that use the Server Virtualization App, but from different hosts.

I am trying to figure out how I could filter on the respective search heads automatically so that each team sees only their hosts' data. Since the app uses custom indexes and source-types, I don't see a way to do it at index time. Any suggestions? Can this be done at search time on the search head?

0 Karma

vasanthmss
Motivator

Hi RomeoG,

Since you have already indexed the data in same index, create / update the roles with "Restrict search terms " parameter.

This may help you.

V
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...