Reporting

Security Best Practices and the default Search & Reporting App

kwkkarl
New Member

Noob here.

I thought I read somewhere that you should not give users access to the default Search and Reporting App. This should be for Admins only.

Instead, you should create a custom app and secure their access by roles and or indexes with the custom app.
Is this correct, And if so, is this documented anywhere?

I mentioned this to a consultant and was told that he was not familiar with this. So I’m wondering if I misunderstood what I read.
And unfortunately I have been not been to find the original document that started me down this path.

Thanks in advance for your replies.

0 Karma

sloshburch
Splunk Employee
Splunk Employee

This probably came from me. I talk a lot about the concept of using apps as Workspaces. The premise is that as the user base of Splunk grows, you would do well to give each group their own app, or Workspace, to work in. This makes the S&R not so cluttered, promotes collaboration with the intimate environment, and constrains the impact of knowledge objects to those working in the workspace.

See Workspace best practices for a Splunk deployment for more information and a link to the Welcome Page Creator for Splunk on Splunkbase which comes with a barebones workspace template.

0 Karma

woodcock
Esteemed Legend

I wouldn't go so far as to disallow access to S&R but I totally agree that every group of users should have their own creative app where they should do all of their work so that it can be managed separately.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I heard of sites blocking access to the S&R app, but nothing says you should do it.

S&R is blocked to prevent the real-time search that runs to populate the "What to Search" panel. In a system with a lot of users, all those real-time searches can tie up a lot of resources. A custom app is usually used as the default app to replace S&R.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...