Security

Field Extraction Restriction

rashi83
Path Finder

Hi,
I want to restrict field extraction capability to users in Splunk system. I want to provide this capability just to Admin users.
If this is not possible , can users create private extractions and only admin can make them global - just trying to put control around the splunk system,

thoughts?

0 Karma

solarboyz1
Builder

can users create private extractions and only admin can make them global

This is exactly how it works. As long as the users do not have write access to the apps, they will only be able to create private objects.

0 Karma

rashi83
Path Finder

@solarboyz1 -What is the name of capability that can control write access to the apps? Could you please share

0 Karma

solarboyz1
Builder

Its not a capability, it's permissions on the app.

App dropdown -> Manage Apps -> {Selected App} Permissions

It lists the roles, and if the have read and/or write permissions.

0 Karma

rashi83
Path Finder

thanks , so I have READ permission to Everyone and Write permission to Admin and Power user only.
But Still I see "normal user" can create global field extractions.

0 Karma

solarboyz1
Builder

https://docs.splunk.com/Documentation/Splunk/7.3.1/Admin/Apparchitectureandobjectownership

To make an object global the user requires the capability:

admin_all_objects capability

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...