⛏️ Get Splunky!
Lv.1Intern
0 XP
0
Home Map Stats Drill Board Log In
Back to Floor
GRC Vault • Room 3

Role-Based Access Control Architecture

In Splunk, the architect designs the RBAC model to enforce least privilege. Roles inherit capabilities and are assigned index access. A SOC Analyst role might have access to `network_*` indexes but not `hr_*` or `finance_*` indexes. Capability restrictions prevent analysts from editing saved searches or exporting large datasets.

The architect also designs audit logging for the security platform itself. Splunk's `_audit` index records all user activity: logins, searches, dashboard views, and data exports. This enables insider threat detection on the Splunk platform and satisfies compliance requirements for audit log protection.

Knowledge Check

Prove your understanding to clear the room (Rewards XP)
❤️❤️❤️
Question 1 of 1
Which Splunk index records all user actions including logins and searches for audit purposes?
A_internal
B_audit
C_introspection
D_telemetry