Getting Data In

RBAC/permissions: Is it possible to restrict a role as only able to search an index from a particular app?

responsys_cm
Builder

My customer has indexed data that inadvertently contains clear-text passwords in it.

There are folks who need to be able to search that data, but aren't privileged enough to have access to see those passwords.

I've put a SEDCMD command in props.conf to obfuscate the password for future events. What I would like to do is create an app with a forms-based search that will run rex with every search and use its sed functionality to strip out the passwords on historical events.

If I grant the user's role access to the index, then they'll be able to see those passwords when they are outside of the app. Is it possible to restrict a role to only being able to search an index from a particular app? Could I do that by setting the app permissions to "this app only" and then put an authentication.conf file in the app that assigns the unprivileged AD group a role that is allowed to search the index?

Thx.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi responsys_cm,
It isn't possible to enable a role to access an index from a predefined App, you can only define access to one or more indexers and one or more Apps.
To do what you want, you should modify all your apps accessed by these users disabling all accesses to raw events (drilldown or search).
I think that the easiest way to proceed is to extract your data, mask and reindex them and at the end delete the old ones.
I can imagine that you have many events, but probably this is the easieste way!
Bye.
Giuseppe

0 Karma

coltwanger
Contributor

I do not believe it's possible to restrict searching an index to an individual app like that WHILE giving them access to other apps. If they have access to the index, then they can search the raw data from whatever app gives them the search bar.

Is dumping out the raw data and bringing it back in (and getting hit with SEDCMD in the process) out of the question?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...