Splunk Enterprise Security

In Splunk Enterprise Security, how do you create a user role with ready-only access?

sesharao92
Explorer

Is there any way to create a user role with read-only access to a specific set of indexes?

0 Karma

mayurr98
Super Champion

Have a look at this, might be useful to you:
https://answers.splunk.com/answers/10582/permissions-on-indexes-and-sourcetypes.html

let me know if this helps!

0 Karma

bangalorep
Communicator

You can create a role with only read access. You can go to settings >> access control >> roles
You can know more from the following link
https://docs.splunk.com/Documentation/Splunk/7.2.3/Admin/Aboutusersandroles

0 Karma

ddrillic
Ultra Champion

Interesting thing as Splunk roles are designed for read access, not for write access and each role has read access to a set of indexes.

If we look at About users and roles

It defines the user role as -

-- this role can create and edit its own saved searches, run searches, edit its own preferences, create and edit event types, and other similar tasks.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...