<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Application Without Authentication in Security</title>
    <link>https://community.splunk.com/t5/Security/Application-Without-Authentication/m-p/72993#M2405</link>
    <description>&lt;P&gt;The first 2 links are dead; is there an archive anywhere?&lt;/P&gt;</description>
    <pubDate>Mon, 13 Apr 2015 20:21:41 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2015-04-13T20:21:41Z</dc:date>
    <item>
      <title>Application Without Authentication</title>
      <link>https://community.splunk.com/t5/Security/Application-Without-Authentication/m-p/72990#M2402</link>
      <description>&lt;P&gt;Could I create an application in splunk that requires no authentication?  Since splunk already lives on our intranet, I'd like to give users access to dashboards without requiring them to log in.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2010 23:23:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Application-Without-Authentication/m-p/72990#M2402</guid>
      <dc:creator>srussellnpr</dc:creator>
      <dc:date>2010-10-19T23:23:12Z</dc:date>
    </item>
    <item>
      <title>Re: Application Without Authentication</title>
      <link>https://community.splunk.com/t5/Security/Application-Without-Authentication/m-p/72991#M2403</link>
      <description>&lt;P&gt;Yes. There are a few things you can do.&lt;/P&gt;

&lt;P&gt;Here's an example site (from the guys who do the SplunkTalk podcast):&lt;BR /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;    &lt;A href="http://bit.ly/splunktalkanalytics" rel="nofollow"&gt;http://bit.ly/splunktalkanalytics&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Take a look at this video blog post:&lt;BR /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;A href="http://blogs.splunk.com/2010/09/27/video-glimpse-into-splunktalk-podcast-analytics-insecure-login-dashboard-tricks/" rel="nofollow"&gt;http://blogs.splunk.com/2010/09/27/video-glimpse-into-splunktalk-podcast-analytics-insecure-login-dashboard-tricks/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;/P&gt;&lt;HR /&gt;&lt;P&gt;&lt;/P&gt;

&lt;P&gt;The gist is that you can use "&lt;A href="http://www.splunk.com/base/Documentation/4.1.5/Developer/ThirdParty#Enable_insecure_login" rel="nofollow"&gt;insecure&lt;/A&gt;" authentication, and embed login credentials into the URL. Then, create a dedicated role for that user, giving it access to on the indexes, search commands, etc. that it actually needs. Maybe even assign a search filter. Also, create a dedicated search app, with just the dashboards you need, and make that the default for the user. Using a separate, stripped-down search head can also help limit your attack surface.&lt;/P&gt;

&lt;P&gt;If you want to use always-on displays, the timeouts can be a problem as well, so see this thread:&lt;BR /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="http://answers.splunk.com/questions/7233/user-specific-browser-session-timeout" rel="nofollow"&gt;http://answers.splunk.com/questions/7233/user-specific-browser-session-timeout&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Remember the common tradeoffs between security and usability apply, so doing this of course involves a bit of additional risk. Provided you're ok with that, this should get you started.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2010 00:18:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Application-Without-Authentication/m-p/72991#M2403</guid>
      <dc:creator>southeringtonp</dc:creator>
      <dc:date>2010-10-20T00:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: Application Without Authentication</title>
      <link>https://community.splunk.com/t5/Security/Application-Without-Authentication/m-p/72992#M2404</link>
      <description>&lt;P&gt;You're awesome southeringtonp!&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2010 00:06:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Application-Without-Authentication/m-p/72992#M2404</guid>
      <dc:creator>srussellnpr</dc:creator>
      <dc:date>2010-10-21T00:06:33Z</dc:date>
    </item>
    <item>
      <title>Re: Application Without Authentication</title>
      <link>https://community.splunk.com/t5/Security/Application-Without-Authentication/m-p/72993#M2405</link>
      <description>&lt;P&gt;The first 2 links are dead; is there an archive anywhere?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2015 20:21:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Application-Without-Authentication/m-p/72993#M2405</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-04-13T20:21:41Z</dc:date>
    </item>
  </channel>
</rss>

