Hello splunkers :)
I have a new issue and I'd like to have your opinion on this.
I created a new custom application that in the search I specify two indexes (eg. index=toto or index=titi).
With a usual user, I can access data only for one index but not from the other.
If I promote my user to admin, he can access data through my custom app for both indexes.
My regular user can access data in these two indexes if he uses the standard Splunk search application.
Is there any mechanism that could block the access to some indexes?
Is there any list of commands that only administrator can execute? (Or rather, is it possible that in my search I use such commands that are blocked?)
I verified in the directory of my apps if I had some permission problem to the XML files or other but it is not the case.
I tried to give all the capabilities to my user....always the same problem :(
Any help is appreciated.
thank you in advance,
Michail
↧