<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: insecure login for one app? in Security</title>
    <link>https://community.splunk.com/t5/Security/insecure-login-for-one-app/m-p/88755#M2948</link>
    <description>&lt;P&gt;Thanks! I do have the enterprise license, now I shall create a separate distributed search instance! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; ( by adding the forwarder license)&lt;/P&gt;</description>
    <pubDate>Thu, 25 Nov 2010 15:29:25 GMT</pubDate>
    <dc:creator>heterodyned</dc:creator>
    <dc:date>2010-11-25T15:29:25Z</dc:date>
    <item>
      <title>insecure login for one app?</title>
      <link>https://community.splunk.com/t5/Security/insecure-login-for-one-app/m-p/88748#M2941</link>
      <description>&lt;P&gt;Hey Team,&lt;/P&gt;

&lt;P&gt;I created a custom app to enable charting, and tried setting up an insecure login feature ( inorder to embed the charts in a webpage), for some reason it is throwing me a 403 forbidden. Our splunk server is configured with LDAP configuration, was just wondering if its possible to change the authentication mode for that particular APP alone? or am I going wrong somewhere? the embed string I am trying to use is &lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk:8000/en_US/account/insecurelogin?username=admin&amp;amp;password=changeme&amp;amp;return_to=/app/TEST/sample_dashboard" rel="nofollow"&gt;http://splunk:8000/en_US/account/insecurelogin?username=admin&amp;amp;password=changeme&amp;amp;return_to=/app/TEST/sample_dashboard&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Thanks once again&lt;/P&gt;

&lt;P&gt;-
Raghu&lt;/P&gt;</description>
      <pubDate>Sat, 13 Nov 2010 21:59:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/insecure-login-for-one-app/m-p/88748#M2941</guid>
      <dc:creator>heterodyned</dc:creator>
      <dc:date>2010-11-13T21:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: insecure login for one app?</title>
      <link>https://community.splunk.com/t5/Security/insecure-login-for-one-app/m-p/88749#M2942</link>
      <description>&lt;P&gt;It's a system-wide feature. You can't enable/disable it on a per-app basis.&lt;/P&gt;

&lt;P&gt;As a workaround, you can create a dedicated instance of Splunk, and enable insecure authentication there, and configure it to be a dedicated search head with just that app.&lt;/P&gt;

&lt;P&gt;See also:
&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;A href="http://answers.splunk.com/questions/8093/application-without-authentication" rel="nofollow"&gt;http://answers.splunk.com/questions/8093/application-without-authentication&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Nov 2010 23:47:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/insecure-login-for-one-app/m-p/88749#M2942</guid>
      <dc:creator>southeringtonp</dc:creator>
      <dc:date>2010-11-13T23:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: insecure login for one app?</title>
      <link>https://community.splunk.com/t5/Security/insecure-login-for-one-app/m-p/88750#M2943</link>
      <description>&lt;P&gt;Did i catch you wrong with dedicated instance? you mean like a dedicated indexer? wherein all forwarders send the data?&lt;/P&gt;</description>
      <pubDate>Sun, 14 Nov 2010 12:44:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/insecure-login-for-one-app/m-p/88750#M2943</guid>
      <dc:creator>heterodyned</dc:creator>
      <dc:date>2010-11-14T12:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: insecure login for one app?</title>
      <link>https://community.splunk.com/t5/Security/insecure-login-for-one-app/m-p/88751#M2944</link>
      <description>&lt;P&gt;Infact while I set up the web.conf within the app, with insecure login, it seems to be permitting insecure login with other apps as well. So I am guessing that web.conf setup is also a system wide feature, I think this woould mean to setup a separate Distributed search head? which would have insecure login?&lt;/P&gt;

&lt;P&gt;-&lt;BR /&gt;
Raghu&lt;/P&gt;</description>
      <pubDate>Sun, 14 Nov 2010 20:18:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/insecure-login-for-one-app/m-p/88751#M2944</guid>
      <dc:creator>heterodyned</dc:creator>
      <dc:date>2010-11-14T20:18:31Z</dc:date>
    </item>
    <item>
      <title>Re: insecure login for one app?</title>
      <link>https://community.splunk.com/t5/Security/insecure-login-for-one-app/m-p/88752#M2945</link>
      <description>&lt;P&gt;Yes - it would be a search head that performs no indexing. It would query the indexer via distributed search. Enabling insecure authentication would apply to all apps installed on that search head. However, a search head does not need to have every app installed. You can install just the app(s) that are needed to render your dashboard.&lt;/P&gt;</description>
      <pubDate>Sun, 14 Nov 2010 23:10:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/insecure-login-for-one-app/m-p/88752#M2945</guid>
      <dc:creator>southeringtonp</dc:creator>
      <dc:date>2010-11-14T23:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: insecure login for one app?</title>
      <link>https://community.splunk.com/t5/Security/insecure-login-for-one-app/m-p/88753#M2946</link>
      <description>&lt;P&gt;Would that require an enterprise license? Our central server is on enterprise license, so basically this search head can query the indexed data right? Shouldnt require a separate license for the search head right? Pardon me for this silly question&lt;/P&gt;</description>
      <pubDate>Sun, 14 Nov 2010 23:28:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/insecure-login-for-one-app/m-p/88753#M2946</guid>
      <dc:creator>heterodyned</dc:creator>
      <dc:date>2010-11-14T23:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: insecure login for one app?</title>
      <link>https://community.splunk.com/t5/Security/insecure-login-for-one-app/m-p/88754#M2947</link>
      <description>&lt;P&gt;Distributed search does require an enterprise license. You could probably get by with the free forwarder license on the search head, but it looks like you'd still need an Enterprise license for the indexer, so it wouldn't help much. See here for the comparison of licenses - &lt;A href="http://www.splunk.com/base/Documentation/4.1.5/Installation/AboutSplunklicenses"&gt;http://www.splunk.com/base/Documentation/4.1.5/Installation/AboutSplunklicenses&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2010 02:20:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/insecure-login-for-one-app/m-p/88754#M2947</guid>
      <dc:creator>southeringtonp</dc:creator>
      <dc:date>2010-11-15T02:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: insecure login for one app?</title>
      <link>https://community.splunk.com/t5/Security/insecure-login-for-one-app/m-p/88755#M2948</link>
      <description>&lt;P&gt;Thanks! I do have the enterprise license, now I shall create a separate distributed search instance! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; ( by adding the forwarder license)&lt;/P&gt;</description>
      <pubDate>Thu, 25 Nov 2010 15:29:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/insecure-login-for-one-app/m-p/88755#M2948</guid>
      <dc:creator>heterodyned</dc:creator>
      <dc:date>2010-11-25T15:29:25Z</dc:date>
    </item>
  </channel>
</rss>

