List of questions
Related questions
Question 6 - SPLK-1005 discussion
A Splunk Cloud administrator is looking to allow a new group of Splunk users in the marketing department to access the Splunk environment and view a dashboard with relevant data. These users need to access marketing data (stored in the marketing_data index), but shouldn't be able to access other data, such as events related to security or operations.
Which approach would be the best way to accomplish these requirements?
Create a new user with access to the marketing_data index assigned.
Create a new role that inherits the user role and remove the capability to search indexes other than marketing_data.
Create a new role that inherits the admin rote and assign access to the marketing_dat.a index.
Create a new role that does not inherit from any other role, turn on the same capabilities as the user role, and assign access to the marketing_data index.
0 comments
Leave a comment first