Splunk Search

Locking down app and role to search only one index, why are users that are assigned this role able to search the main index?

avalle
Path Finder

Hello all,

I have looked at documentation and a few of the questions on here and have tried it all.
I have created an app (let's call it ppl app), assigned a role (let's call it ppl role) to it, and that role is locked down to one index (lets call it the ppl index).
I have given the app access to the ppl role.
I have restricted that role to search index=ppl only.

Gave it the following capabilities:
accelerate_search
change_own_password
get_typeahead
pattern_detect
search

Why are the users assigned to this role able to search the main index?
Am I missing a step somewhere?

0 Karma
1 Solution

avalle
Path Finder

I think I found the answer...........there is a delay in LDAP synch. I just had to wait it out and it worked.

View solution in original post

0 Karma

somesoni2
Revered Legend

1) Check if the ppl role is inheriting any other role (say user role)?
2) There are two index related settings available while creating a role, "Indexes searched by default" and "Indexes", make sure that only your ppl index is selected in both the settings for ppl role.

0 Karma

avalle
Path Finder

I think I found the answer...........there is a delay in LDAP synch. I just had to wait it out and it worked.

0 Karma

gtriSplunk
Path Finder

Are the users members of any other role? If a user is a member of multiple roles they will be able to search indexes that are a member of any of the roles.

0 Karma

avalle
Path Finder

Yes I am sure! we had an LDAP delay.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...