Security

Is it necessary to create indices, both on Search Head and Indexer?

davidcruz
Explorer

Hello guys,
After creating my indices in the Indexer and configure it as a search peer of my Search Head, I was able to search through every index that I've created in the Indexer.
BUUUT, when defining a role in the Search Head, I can't limit those indices because the index list only shows the Search Head indices.... Is there any way to resolve this, without duplicating these indices on the Search Head?
Thanks in advance 🙂

0 Karma

woodcock
Esteemed Legend

Yes, if you would like to use the user/role settings for index values AND like to have the in-search helps know about and suggest index values, then you must define them on the Search Head, too.

0 Karma

somesoni2
Revered Legend

If you want to edit role's index restriction from Splunk Web UI, you'd need those indexes to be created in Search Heads as well. Alternative to this would be setup role using configuration files on Search Head, where you can just mention the name of the indexes that are available in Indexers, without having them created in SH. See this:
http://docs.splunk.com/Documentation/Splunk/7.0.3/Security/Addandeditroleswithauthorizeconf

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...