Splunk Search

Limit Queries based on user accounts

tier2ops
Explorer

I would like to spearate general query utilization between various groups. Example: only allowing Scruirty personnel the ability to look at logs from specific security devices.

Is this possible?

0 Karma

Ayn
Legend

Sure. You can do this by creating a role, say, "security_personnel", assigning search term restrictions to that role and then finally adding the users you want to that role. In the web UI under Manager >> Access controls >> Roles >> (your chosen role), there is a field called "Restrict search terms" that you can use to add whatever restrictions you want for that role. These search terms will be implicitly added to any search that users of this role issue.

More information on users and roles is available in the Admin manual here: http://www.splunk.com/base/Documentation/latest/Admin/Addusersandassignroles

Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...