Security

Keep one type of data separated and limit access

Mark_Barrett
Explorer

I'm interested in importing a data type which is limited-access information and not accessible to most System Admins in our environment. However, I'm not sure how to ensure that once it has been brought into Splunk, to keep it locked down so that only specified Splunk users would be able to view this data.
I'm guessing that this data could be placed into a separate index file, but beyond that I have no idea how to set up the access (or if that's even possible?) Would be interested in finding any solutions, including any kind of tutorial or best-practice document out there to explain how to do this.

Tags (1)
0 Karma
1 Solution

tskinnerivsec
Contributor

You definitely want to ingest that data into its own index, then you can limit the users who have rights to view that index. An index is the smallest unit that you can apply an ACL to. Are you using local splunk logins or are you using ldap authentication? Basically, you create roles within splunk and either map users to those roles within splunk or you can map ldap groups to those roles and control the group membership in a directory service like Microsoft Active Directory.

View solution in original post

tskinnerivsec
Contributor

You definitely want to ingest that data into its own index, then you can limit the users who have rights to view that index. An index is the smallest unit that you can apply an ACL to. Are you using local splunk logins or are you using ldap authentication? Basically, you create roles within splunk and either map users to those roles within splunk or you can map ldap groups to those roles and control the group membership in a directory service like Microsoft Active Directory.

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...