Is it possible to filter results in a lookup-file with filters defined in "srchFilter" in authorize.conf?
Example lookup:
[role-lookup.csv]
system,role
system01,linux
system02,linux
system03,windows
system04,windows
Example authorize.conf
[role_linux]
srchFilter = role=linux
Example search
| inputlookup role-lookup.csv
This returns all the lines in the lookup-file, I only want the first two with the role defined in my srchFilter.
Is this possible to achieve somehow? I would like to populate a dashboard dropdown with only the choices the user actually has access to.
I tried some silly workarounds like makeresults and appending the CSV data to trick Splunk into applying the srchFilter rule, but I can't find a way to make this work.
... View more