Security

How to restrict users access to real time data and searches?

sravankaripe
Communicator

i want to restrict all users access to real time data and real time searches. how can i do this?

0 Karma
1 Solution

sravankaripe
Communicator

i want to re-stick all users except admin to access real time data and real time searches

0 Karma

sravankaripe
Communicator

Thanks its working

0 Karma

somesoni2
Revered Legend

Go through the instruction on section "Disable real-time search for a user or role" on the same page. Basically remove the capability rtsearch and schedule_rtsearch for the all roles except admin role. Do do this from backend, update the authorize.conf file.

direct link:
https://docs.splunk.com/Documentation/Splunk/6.5.0/Search/Restrictrealtimesearch#Disable_real-time_s...

0 Karma

sravankaripe
Communicator

can we do it from back end ?

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...