search filter

noun

A limited type of Splunk search string that is defined for and applied to a given role through Manager > Roles or authorize.conf, thereby constraining what data that users in the role can access via search.

Search filters are additive, so if a user is a member of more than one role with search filters applied, all applicable search filters are effectively joined with a Boolean 'OR'.

For more information

In the Admin Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time