Splunk Search

System eventtypes "internal_search_terms", "splunkd-access", "splunkd-log"

kandersen
New Member

Hello, I want to limit the access for some external users to all eventtypes.

There are 3 system-default-eventtypes remaining: "internal_search_terms", "splunkd-access", "splunkd-log".
The privileges of these 3 seems to be not changeable.
What are the purpose of these?
And how could I block them for specific users?

0 Karma

janispelss
Path Finder

Seems that those are eventtypes that only apply to Splunk's internal events. So if the users you want to restrict don't have the access to the internal indexes (and they probably shouldn't), they won't be able to use the eventtypes, even though they can see the definitions.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...