Dashboards & Visualizations

Restrict Search Terms

zacksoft
Contributor

We have some external users, whom we want to be able to see some dashboards we have created.
However, we do not want them to be able to make search on the search-head.

e.g. Dashboard item has a query like host = baloney.pipe source=B_Circuit | some column chart visualization
The users should be able to see the dashboard However if they want to search host = baloney.pipe source=B_Circuit on a search head they shouldn't get any results. (Only dashboard access to view ; No access to make any search on the index/host etc.. through search head)

Would using the 'Restrict Search Terms' option while creating a role help us achieve this functionality ?

0 Karma

ryhluc01
Communicator

Edit what you allow for them to do within the user roles.

0 Karma

zacksoft
Contributor

I haven't created any role for them yet. I am still deciding what roles or capabilities will allow them to see the dashboard output but not able to make any query .

0 Karma

koshyk
Super Champion

There is NO true way to restrict user from accessing data unless it is done at "index" level (ie. role vs index)
If the user is clever, they can tune the Search into URL parameters and get the information even if any restrictions on dashboard is done

0 Karma

somesoni2
Revered Legend

The "Restrict Search Terms" applies to all searches, include the one launched from dashboards, so that would not work. Have a read at this: (I believe this is still true for current version)
https://answers.splunk.com/answers/487844/limit-user-access-to-view-dashboard-only.html

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...