Limiting uberAgent search head app to one index without Splunk Roles



I was wondering if it is possible to limit the data that the uberAgent search head app sees when launched?  We have multiple indexes and when logged into the search head as an admin account and launching the uberAgent app it shows all data from all uberAgent indexes.  Is it possible to limit the data to a specific index without having to log out and back into splunk using Roles that limit index access?



1 comment

Please sign in to leave a comment.