All Apps and Add-ons

How can I restrict a user role to only access and search data for a certain Splunk app?

vvelpuri
Explorer

I have a user and I created a role call 'X'. I updated the role with Restrict search terms "Splunk App for AWS", but the user is unable to search the data on search head. Do we have to provide any access to the user in order to search for the data?

0 Karma

woodcock
Esteemed Legend

You cannot. The only secure way to restrict access to data is to put it in a separate index and then remove that index from the role's setting.

0 Karma

lguinn2
Legend

You can't put the name of an app in the search terms - that will not work at all! Here is what you need to do:

In the role X: make sure that the allowed indexes and default indexes are correct. This is how you control access to data. Make the "Splunk App for AWS" the default app for role X. When the user logs in, he/she will automatically be in the default app.

For each app: Go to Manage Apps. Check the permissions. For the "Splunk App for AWS," make sure that the role X has at least "read" permissions. For all other apps, make sure that role X has no permisssions. This will probably require that you change the permissions for many apps, which often default to "Read" and even "Write" for everyone.

nawazns5038
Builder

For each app: Go to Manage Apps. Check the permissions. For the "Splunk App for AWS," make sure that the role X has at least "read" permissions. For all other apps, make sure that role X has no permisssions. This will probably require that you change the permissions for many apps, which often default to "Read" and even "Write" for everyone.

Is it okay to do that in the search head cluster from the UI. Or is it something that is needed to be done from the deployer.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...