<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is the access/account type needed for splunk user in linux to use universal fowarder? in Security</title>
    <link>https://community.splunk.com/t5/Security/What-is-the-access-account-type-needed-for-splunk-user-in-linux/m-p/319755#M12736</link>
    <description>&lt;P&gt;Thanks for your respond; created a category 0 to accommodate the requirement.&lt;/P&gt;</description>
    <pubDate>Tue, 27 Mar 2018 19:20:11 GMT</pubDate>
    <dc:creator>dban2005</dc:creator>
    <dc:date>2018-03-27T19:20:11Z</dc:date>
    <item>
      <title>What is the access/account type needed for splunk user in linux to use universal fowarder?</title>
      <link>https://community.splunk.com/t5/Security/What-is-the-access-account-type-needed-for-splunk-user-in-linux/m-p/319753#M12734</link>
      <description>&lt;P&gt;I have few linux servers reporting to a splunk indexer. While installing the UF on the linux servers, the splunk user has been created automatically and we are running the splunk service using that splunk user. As it created the splunk user with home directory as /opt/splunkforwarder, we need to maintain it for security reason. Can someone please advise in which of the following category this UF splunk user should considered?&lt;/P&gt;

&lt;P&gt;Category a: user with ssh shell access&lt;BR /&gt;
Category b: user with scp/sftp access&lt;BR /&gt;
Category c: access with su to non-root users&lt;BR /&gt;
Category d: access with su to root &lt;/P&gt;

&lt;P&gt;I do not think I can categorized with any of the above. If not, then how I can define the splunk user with respect to the linux servers where the UF has been installed.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 23:26:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/What-is-the-access-account-type-needed-for-splunk-user-in-linux/m-p/319753#M12734</guid>
      <dc:creator>dban2005</dc:creator>
      <dc:date>2018-01-18T23:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: What is the access/account type needed for splunk user in linux to use universal fowarder?</title>
      <link>https://community.splunk.com/t5/Security/What-is-the-access-account-type-needed-for-splunk-user-in-linux/m-p/319754#M12735</link>
      <description>&lt;P&gt;By default the splunk user will not have any remote access to your server, and will have no sudo/root access.&lt;/P&gt;

&lt;P&gt;It is by design a "standard" non privileged user.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 13:52:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/What-is-the-access-account-type-needed-for-splunk-user-in-linux/m-p/319754#M12735</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2018-01-19T13:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: What is the access/account type needed for splunk user in linux to use universal fowarder?</title>
      <link>https://community.splunk.com/t5/Security/What-is-the-access-account-type-needed-for-splunk-user-in-linux/m-p/319755#M12736</link>
      <description>&lt;P&gt;Thanks for your respond; created a category 0 to accommodate the requirement.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Mar 2018 19:20:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/What-is-the-access-account-type-needed-for-splunk-user-in-linux/m-p/319755#M12736</guid>
      <dc:creator>dban2005</dc:creator>
      <dc:date>2018-03-27T19:20:11Z</dc:date>
    </item>
  </channel>
</rss>

