Getting Data In

Is it possible to create a role-based search filter on a specific index?

pkeller
Contributor

We'd like to grant access to an additional index to a role, but we only want the members to be able to view 2 sourcetypes in that index.

I added a role called: foo_filtered
I added a search filter of: "service=Amazon OR service=Ebay" to that role
I gave that role access to an index named "vendor"

Their existing role foo_mail has access to search the "mail" and "spam" indexes.

So, when I add the foo_filtered role to their group, ALL searches (regardless of index) apply the filter. I only want the filter applied if they're searching the "vendor" index.

Is this even possible?
Thank you

0 Karma
1 Solution

masonmorales
Influencer

This is not possible with the current version of Splunk, unfortunately. You can submit an enhancement request on the Support Portal and they might add it in the future though.

View solution in original post

0 Karma

masonmorales
Influencer

This is not possible with the current version of Splunk, unfortunately. You can submit an enhancement request on the Support Portal and they might add it in the future though.

0 Karma

wryanthomas
Contributor

Is this still true?

0 Karma
Get Updates on the Splunk Community!

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...