Security

Remove search ability users

mmoermans
Path Finder

Hi there,

I'm trying to set up a monitor/manager account which only has access to dashboards but cannot search through indexes himself.
Where do you set this permission?

0 Karma

inventsekar
SplunkTrust
SplunkTrust

After creating user, create a role for this user and assign this role only the read permission for dashboard.

Please, create a role for this user before create this user, thus you can assign this role for this user and assign only the read permission for this user role.

if you don't want that user cannot search, either:

under Indexes, don't select no index, leave input Selected search indexes blank and save. Thus, your user cannot run search.

create an app for this dashboard and in the default nav four your app, only call the dashboards which user will see like this for example:

After do this edit your user and give it this app context by default

https://answers.splunk.com/answers/224735/how-to-restrict-a-users-role-to-only-view-a-dashbo.html

0 Karma

inventsekar
SplunkTrust
SplunkTrust

edit - not sure if this can be done.. lets wait for others answers.

not sure of this one, but please check this Capability
"search" --- Run searches,
"srchIndexesAllowed"

but still, we can add or remove the search capability, but there is no separate capability for granting the dashboard. i think its not possible. lets wait for others answers.

"search" --- Run searches,
"srchIndexesAllowed" - User is allowed to search indexes.
https://docs.splunk.com/Documentation/Splunk/6.6.2/Security/Rolesandcapabilities

0 Karma

mmoermans
Path Finder

srchIndexesAllowed only lets you definine which indexes can be searched.
If srchIndexesAllowed is empty then no results are found by Monitor user (in dashboards too).

[role_monitor]
cumulativeRTSrchJobsQuota = 0
cumulativeSrchJobsQuota = 0
importRoles = user_no_index
srchIndexesAllowed = network
srchIndexesDefault = network
srchMaxTime = 0

0 Karma

inventsekar
SplunkTrust
SplunkTrust

oops, my mistake. when i read the question, this issue came to my mind, but then missed it.

please check this Capability
"search" --- Run searches.

but still, we can add or remove the search capability, but there is no separate capability for granting the dashboard. i think its not possible. lets wait for others answers.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...