Skip to content
This repository was archived by the owner on Sep 2, 2025. It is now read-only.

Commit 570f6b6

Browse files
Merge pull request #2442 from splunk/tcarter-OD-6555-IndexRestrict
tcarter-OD-6555-IndexRestrict
2 parents c0770e4 + 5bba367 commit 570f6b6

File tree

2 files changed

+63
-37
lines changed

2 files changed

+63
-37
lines changed

logs/scp.rst

Lines changed: 31 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -50,9 +50,9 @@ Splunk Observability Cloud
5050

5151
In Splunk Observability Cloud, do the following:
5252

53-
1. Go to :guilabel:`Settings > Log Observer Connect` and select :guilabel:`Add new connection`. If you don't see :guilabel:`Log Observer Connect` in :guilabel:`Settings`, you are not an administrator in Splunk Observability Cloud. Contact your organization's Splunk Observability Cloud administrator to perform this integration.
53+
1. Go to :guilabel:`Settings` then :guilabel:`Log Observer Connect` and select :guilabel:`Add new connection`. If you don't see :guilabel:`Log Observer Connect` in :guilabel:`Settings`, you are not an administrator in Splunk Observability Cloud. Contact your organization's Splunk Observability Cloud administrator to perform this integration.
5454

55-
2. Select :guilabel:`Splunk Cloud Platform`.
55+
2. Select :guilabel:`Splunk Cloud Platform`. Next, log in to Splunk Cloud Platform as an administrator and follow the instructions in the next section.
5656

5757
Splunk Cloud Platform
5858
----------------------------------------------------------------
@@ -61,48 +61,48 @@ To configure the Splunk Cloud service account user in the following section you
6161

6262
In Splunk Cloud Platform, follow the instructions in the guided setup for the integration to do the following:
6363

64-
1. To configure a role in Splunk Cloud Platform for the Log Observer Connect service account, go to :guilabel:`Settings > Roles`.
64+
1. To configure a role in Splunk Cloud Platform for the Log Observer Connect service account, select :guilabel:`Settings` then select :guilabel:`Roles`.
6565

6666
.. image:: /_images/logs/setupLOC1.png
6767
:width: 100%
6868
:alt: This screenshot shows how to go to Roles in Splunk Cloud Platform where you will set up a service account for Log Observer Connect.
6969

70-
2. Select the role you want to use for the Log Observer Connect service account. The service account is a user role that can access the specific Splunk Cloud Platform indexes that you want your users to search in Log Observer Connect.
70+
Select the role you want to use for the Log Observer Connect service account. The service account is a user role that can access the specific Splunk Cloud Platform indexes that you want your users to search in Log Observer Connect.
7171

72-
3. On the :guilabel:`Capabilities` tab, ensure that ``edit_tokens_own`` and ``search`` are selected. Also, ensure that ``indexes_list_all`` is not selected.
72+
2. On the :guilabel:`Indexes` tab in the :guilabel:`Included` column, deselect :guilabel:`*(All internal indexes)` and select the indexes that you want users to query in Log Observer Connect.
7373

74-
.. image:: /_images/logs/CapabilitiesTab1.png
74+
.. image:: /_images/logs/IndexesTab1.png
7575
:width: 100%
76-
:alt: This screenshot shows the Capabilities tab in user configuration.
76+
:alt: This screenshot shows the Indexes tab in user configuration.
7777

78-
4. On the :guilabel:`Indexes` tab in the :guilabel:`Included` column, deselect :guilabel:`*(All internal indexes)` and select the indexes that you want users to query in Log Observer Connect.
78+
3. On the :guilabel:`Capabilities` tab, ensure that ``edit_tokens_own`` and ``search`` are selected. Also, ensure that ``indexes_list_all`` is not selected.
7979

80-
.. image:: /_images/logs/IndexesTab1.png
80+
.. image:: /_images/logs/CapabilitiesTab1.png
8181
:width: 100%
82-
:alt: This screenshot shows the Indexes tab in user configuration.
82+
:alt: This screenshot shows the Capabilities tab in user configuration.
8383

84-
5. On the :guilabel:`Resources` tab, enter a :guilabel:`Standard search limit` of 40 for both :guilabel:`Role search job limit` and :guilabel:`User search job limit`. Enter 0 for :guilabel:`Real-time search limit` for both role and user search job limits.
84+
4. On the :guilabel:`Resources` tab, enter a :guilabel:`Standard search limit` of 40 for both :guilabel:`Role search job limit` and :guilabel:`User search job limit`. Enter 0 for :guilabel:`Real-time search limit` for both role and user search job limits.
8585

8686
The limit of 40 assumes that you have 10 Log Observer Connect users. To determine your ideal :guilabel:`Standard search limit`, multiply the number of Log Observer Connect users you have by 4. For example, if you have 20 Log Observer users, enter a :guilabel:`Standard search limit` of 80 for both :guilabel:`Role search job limit` and :guilabel:`User search job limit`.
8787

8888
.. image:: /_images/logs/ResourcesTab1.png
8989
:width: 100%
9090
:alt: This screenshot shows recommended configuration for role search job limit and user search job limit.
9191

92-
6. Now, in the :guilabel:`Role search time window limit` section of the :guilabel:`Resources` tab, select :guilabel:`Custom time` and enter 2592000 seconds (30 days) for the maximum time window for searches for this role. Do not use commas when entering numbers. For the earliest searchable event time for this role, select :guilabel:`Custom time` and enter 7776000 seconds (90 days). In the :guilabel:`Disk space limit` section enter a :guilabel:`Standard search limit` of 1000 MB.
92+
5. Now, in the :guilabel:`Role search time window limit` section of the :guilabel:`Resources` tab, select :guilabel:`Custom time` and enter 2592000 seconds (30 days) for the maximum time window for searches for this role. Do not use commas when entering numbers. For the earliest searchable event time for this role, select :guilabel:`Custom time` and enter 7776000 seconds (90 days). In the :guilabel:`Disk space limit` section enter a :guilabel:`Standard search limit` of 1000 MB. Select :guilabel:`Save`.
9393

9494
.. image:: /_images/logs/ResourcesTab2.png
9595
:width: 100%
9696
:alt: This screenshot shows recommended configuration for role search time window limit and disk space limit.
9797

98-
7. Next, in Splunk Cloud Platform, go to :guilabel:`Settings > Users` and create the user for the Log Observer Connect service account. In the :guilabel:`Assign roles` section, assign to the user the role you created in the preceeding steps for the Log Observer Connect service account.
98+
6. Next, in Splunk Cloud Platform, go to :guilabel:`Settings` then :guilabel:` Users` and create the user for the Log Observer Connect service account. In the :guilabel:`Assign roles` section, assign to the user the role you created in the preceeding steps for the Log Observer Connect service account.
9999

100100
.. image:: /_images/logs/CreateUser.png
101101
:width: 100%
102102
:alt: The Create user page in Splunk Cloud Platform where you can assign a user to the service account role.
103103

104104

105-
8. Add a Workload Rule in Splunk Cloud Platform to limit Log Observer Connect searches to 5 minutes. This limit maintains a responsive experience for Log Observer users and reduces the chances that Log Observer Connect searches are queued. Follow the guidance in :new-page:`Create a Workload Rule in Splunk Web <https://docs.splunk.com/Documentation/SplunkCloud/9.2.2403/Admin/CreateWLMRules#Create_a_workload_rule_in_Splunk_Web>` and configure the rule as follows:
105+
7. Add a Workload Rule in Splunk Cloud Platform to limit Log Observer Connect searches to 5 minutes. This limit maintains a responsive experience for Log Observer users and reduces the chances that Log Observer Connect searches are queued. Follow the guidance in :new-page:`Create a Workload Rule in Splunk Web <https://docs.splunk.com/Documentation/SplunkCloud/9.2.2403/Admin/CreateWLMRules#Create_a_workload_rule_in_Splunk_Web>` and configure the rule as follows:
106106

107107
.. code-block:: none
108108
@@ -118,17 +118,28 @@ In Splunk Cloud Platform, follow the instructions in the guided setup for the in
118118

119119
.. _download-certificate:
120120

121-
9. Secure a connection to your Splunk Cloud Platform instance in Splunk Observability Cloud. See :ref:`logs-scp-prereqs` for more information on the IPs to allow.
121+
8. Secure a connection to your Splunk Cloud Platform instance in Splunk Observability Cloud. See :ref:`logs-scp-prereqs` for more information on the IPs to allow.
122+
123+
* To get help from Splunk Support, :ref:`Submit a support ticket <support-ticket>`.
124+
125+
* To do it yourself, add your public IPv4 address to your Splunk Cloud Platform allow list by following instructions in :new-page:`Add subnets to IP allow lists <https://docs.splunk.com/Documentation/SplunkCloud/latest/Admin/ConfigureIPAllowList#Add_subnets_to_IP_allow_lists>`.
122126

123-
* To get help from Splunk Support, :ref:`Submit a support ticket <support-ticket>`.
127+
9. Go back to the Log Observer Connect guided setup and select :guilabel:`Next`. Enter the following:
128+
129+
* Connection name (Be sure to give each connection a unique name.)
130+
131+
* Service account username
132+
133+
* Password
134+
135+
* Splunk platform URL ``https://<stackname>.splunkcloud.com:8089``
124136

125-
* To do it yourself, add your public IPv4 address to your Splunk Cloud Platform allow list by following instructions in :new-page:`Add subnets to IP allow lists <https://docs.splunk.com/Documentation/SplunkCloud/latest/Admin/ConfigureIPAllowList#Add_subnets_to_IP_allow_lists>`.
137+
10. Remove your IPv4 address from the IP allowlist that you added in step 9. If you are in a GCP environment, do not remove the additional GCP IP addresses that you added in step 8. Select :guilabel:`Next`.
126138

127-
10. Go back to the Log Observer Connect guided setup and select :guilabel:`Next`. Enter your service account username, password, and Splunk platform URL ``https://<stackname>.splunkcloud.com:8089`` to complete the guided setup.
139+
11. On the :guilabel:`Configure permissions` page of the guided setup, select the Splunk Observability Cloud users who you want to give access to this connection and the associated Splunk Cloud Platform indexes.
128140

129-
11. Remove your IPv4 address from the IP allowlist that you added in step 9. If you are in a GCP environment, do not remove the additional GCP IP addresses that you added in step 8.
141+
12. Select :guilabel:`Save and activate`.
130142

131-
12. Make sure to give each connection a unique name on the final page of the Log Observer Connect guided setup.
132143

133144
.. note:: Manage concurrent search limits using your current strategy in Splunk Cloud Platform. All searches initiated by Log Observer Connect users go through the service account you create in Splunk Cloud Platform. For each active Log Observer Connect user, four back-end searches occur when a user performs a search in Log Observer Connect. For example, if there are three users accessing Log Observer Connect at the same time, the service account for Log Observer Connect initiates approximately 12 searches in Splunk Cloud Platform.
134145

0 commit comments

Comments
 (0)