Security

Is it possible to restrict the capability "indexes_edit " to specific indexes?

jbrocks
Communicator

Title says it all.

We want to expand the "user" Role to create scheduled Reports (schedule_search) and write them to summary index, for which a user capability "indexes_edit". Otherwise, he will not be able to choose an index to write when editing the report.

Is it possible to restrict the "indexes_edit" capability to only write to a specific index and not to all indexes per default? I tried to restrict it by the "srchIndexesAllowed" but this does not have any effect.

0 Karma
1 Solution

prakash007
Builder

I don't think you can do that and it's not a good idea, indexes_edit would allow user to have access to all indexes when they navigate through settings--->data(indexes). That should be a admin-role capability....
Even if you create a new role with indexes_edit and restrict to specific index, they get access to all indexes...

It's a known issue in 7.2.1..
http://docs.splunk.com/Documentation/Splunk/7.2.1/ReleaseNotes/KnownIssues#Splunk_Web_and_interface_...
http://docs.splunk.com/Documentation/Splunk/7.2.1/Security/Rolesandcapabilities#List_of_capabilities

View solution in original post

0 Karma

prakash007
Builder

I don't think you can do that and it's not a good idea, indexes_edit would allow user to have access to all indexes when they navigate through settings--->data(indexes). That should be a admin-role capability....
Even if you create a new role with indexes_edit and restrict to specific index, they get access to all indexes...

It's a known issue in 7.2.1..
http://docs.splunk.com/Documentation/Splunk/7.2.1/ReleaseNotes/KnownIssues#Splunk_Web_and_interface_...
http://docs.splunk.com/Documentation/Splunk/7.2.1/Security/Rolesandcapabilities#List_of_capabilities

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...