Splunk Search

limit user access to dashboard only

gurinderbhatti
Path Finder

I need to provision new users for splunk access. Yet i dont want to have access to perform any searches , create reports/alerts, do any of that. Simply when they log in, they are presented with a dashboard we've created for them.
Is there a way to do this?
Thanks in advance.

the_wolverine
Champion

There isn't currently a good way to do this. You could preschedule the searches and remove all the clicks and give the user read access, however, its a lot of wasted resource to schedule searches that will only be consumed when the user needs to look at the dashboard.

There should be a special role which would allow an admin to map a group for access to only a dashboard (clicks only) with no capability to search manually. Perhaps this could be done with a "run-as" feature that could be configurable in the dashboard. The user cannot actually run the searches, but when loaded via the dashboard, those searches are "run-as" a user/role with the proper permissions to do so.

0 Karma

rwissSLNL
Engager

Maybe it is a option for you to make the reports embedded and create a webpage that included the reports?

You need to schedule the reports so, they will not see live data but if you schedule every 5 minutes if that is possible in you case than you have a solution. Not native Splunk but maybe it helps you.

0 Karma

pingpangbubai
Explorer

hi, I've tried your suggest, scrub the permission of dashboard_live and flashtimeline to the boardUser, but when the user of boardUser log in, there is also auto-search-bar blow, I want to screen only dashboard and restrict other users to see auto-search-bar, could you give me some suggestion? 3q!

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...