Security

How can I make sure a role setting takes precedence over other role settings?

twinspop
Influencer

I have a user that belongs to a few roles that use LDAP for auth. These roles have srchMaxTime set to 600. I need to cap the user at 300 seconds for srchMaxTime. I have set-up 2 roles named aaa_search_abuser and zzz_search_abuser with this setting, and assigned the user to those roles (in addition the the other roles he belongs to). However, the user still shows with a 600 srchMaxTime. It seems like the role engine is choosing the highest value, not any sort of order-based process.

How can I make sure a role setting takes precedence over other role settings?

thanks

0 Karma

jkat54
SplunkTrust
SplunkTrust

According to authorize.conf.spec srchMaxTime inherits the maximum from the other roles.

http://docs.splunk.com/Documentation/Splunk/6.5.1/admin/Authorizeconf

Looks like you need a role specifically for this user.

0 Karma

ddrillic
Ultra Champion
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...