Security

Dashboard Permission - View dashboard but don't have access to index

rafael_oliveira
New Member

I create a Dashboard and I want to share this Dashboard with other Team, but this team don't have access for the index.
How I share this Dashboard without giving permission in this index.
I can not give permission to this index because I have sensitive information.

0 Karma

secrecys
Explorer

1) Create the Reports to be used in the dashboard;
2) Schedule the reports;
3) Add the Reports to the Dashboard as panels;
4) Share both the reports and dashboard with that role.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rafael_oliveira,
this is possible (not easy but possible!) only if this Team hasn't access to the search dashboards.
In other words, you should deny all direct accesses to Splunk search dashboards: disabling all the "Open in search" buttons of all your dashboards' panels in every App they cn use and the "Search and Reporting" App for them, so they can only see data in this dashboard.
I did it some years ago but it was a very particular use case with users with very few features.

Ciao.
Giuseppe

0 Karma

rafael_oliveira
New Member

I read about that, but these users still needing access to do Search, maybe I can add some permission only for Dashboard? Like each user can see the data only in the Dashboard not in the Search

0 Karma

isoutamo
SplunkTrust
SplunkTrust

I haven't try, but if you first create reports and run those with your privileges and add those to dashboard as elements.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...