Splunk Search

Limit Queries based on user accounts

tier2ops
Explorer

I would like to spearate general query utilization between various groups. Example: only allowing Scruirty personnel the ability to look at logs from specific security devices.

Is this possible?

0 Karma

Ayn
Legend

Sure. You can do this by creating a role, say, "security_personnel", assigning search term restrictions to that role and then finally adding the users you want to that role. In the web UI under Manager >> Access controls >> Roles >> (your chosen role), there is a field called "Restrict search terms" that you can use to add whatever restrictions you want for that role. These search terms will be implicitly added to any search that users of this role issue.

More information on users and roles is available in the Admin manual here: http://www.splunk.com/base/Documentation/latest/Admin/Addusersandassignroles

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...