<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Should we run Splunk as root or non-root user? in Security</title>
    <link>https://community.splunk.com/t5/Security/Should-we-run-Splunk-as-root-or-non-root-user/m-p/143573#M4397</link>
    <description>&lt;P&gt;&amp;gt; Splunk recommends that you don't run as root. &lt;/P&gt;

&lt;P&gt;I'm looking for a citation in the online docs, but not finding any specific recommendation. A recommendation from Splunk would be helpful in forming or justifying our own policy. All I have found so far is &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.3/installation/RunSplunkasadifferentornon-rootuser"&gt;Run Splunk Enterprise as a different or non-root user&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 28 May 2015 14:24:30 GMT</pubDate>
    <dc:creator>jspears</dc:creator>
    <dc:date>2015-05-28T14:24:30Z</dc:date>
    <item>
      <title>Should we run Splunk as root or non-root user?</title>
      <link>https://community.splunk.com/t5/Security/Should-we-run-Splunk-as-root-or-non-root-user/m-p/143565#M4389</link>
      <description>&lt;P&gt;Should we run Splunk as root or non-root user? Which way is better?&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
-Ha&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2014 16:50:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Should-we-run-Splunk-as-root-or-non-root-user/m-p/143565#M4389</guid>
      <dc:creator>hadinh</dc:creator>
      <dc:date>2014-07-15T16:50:24Z</dc:date>
    </item>
    <item>
      <title>Re: Should we run Splunk as root or non-root user?</title>
      <link>https://community.splunk.com/t5/Security/Should-we-run-Splunk-as-root-or-non-root-user/m-p/143566#M4390</link>
      <description>&lt;P&gt;Splunk recommends that you don't run as root.  &lt;/P&gt;

&lt;P&gt;Other info: &lt;A href="http://wiki.splunk.com/Community:DeployHardenedSplunk"&gt;Deploying Splunk&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2014 17:09:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Should-we-run-Splunk-as-root-or-non-root-user/m-p/143566#M4390</guid>
      <dc:creator>rmorlen</dc:creator>
      <dc:date>2014-07-15T17:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: Should we run Splunk as root or non-root user?</title>
      <link>https://community.splunk.com/t5/Security/Should-we-run-Splunk-as-root-or-non-root-user/m-p/143567#M4391</link>
      <description>&lt;P&gt;Best practice in general is to run applications as non-admin users whenever possible. This is a defense-in-depth thing - if an attacker were somehow to be able to compromise the Splunk instance in one way or another and access the underlying operating system through it, it's obviously preferable that Splunk (and therefore the attacker in our scenario) doesn't have administrative privileges.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2014 17:19:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Should-we-run-Splunk-as-root-or-non-root-user/m-p/143567#M4391</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2014-07-15T17:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: Should we run Splunk as root or non-root user?</title>
      <link>https://community.splunk.com/t5/Security/Should-we-run-Splunk-as-root-or-non-root-user/m-p/143568#M4392</link>
      <description>&lt;P&gt;Thanks for the information.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jul 2014 02:43:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Should-we-run-Splunk-as-root-or-non-root-user/m-p/143568#M4392</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-07-16T02:43:27Z</dc:date>
    </item>
    <item>
      <title>Re: Should we run Splunk as root or non-root user?</title>
      <link>https://community.splunk.com/t5/Security/Should-we-run-Splunk-as-root-or-non-root-user/m-p/143569#M4393</link>
      <description>&lt;P&gt;Thanks for the information.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jul 2014 02:43:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Should-we-run-Splunk-as-root-or-non-root-user/m-p/143569#M4393</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-07-16T02:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: Should we run Splunk as root or non-root user?</title>
      <link>https://community.splunk.com/t5/Security/Should-we-run-Splunk-as-root-or-non-root-user/m-p/143570#M4394</link>
      <description>&lt;P&gt;Thanks for your info.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jul 2014 12:12:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Should-we-run-Splunk-as-root-or-non-root-user/m-p/143570#M4394</guid>
      <dc:creator>hadinh</dc:creator>
      <dc:date>2014-07-16T12:12:10Z</dc:date>
    </item>
    <item>
      <title>Re: Should we run Splunk as root or non-root user?</title>
      <link>https://community.splunk.com/t5/Security/Should-we-run-Splunk-as-root-or-non-root-user/m-p/143571#M4395</link>
      <description>&lt;P&gt;Seems the local system account on Windows (default for Splunk Windows installs) is a very near equivalent of root on Unix, however I don't think that is called out as a security risk the same way as root is.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Aug 2014 13:49:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Should-we-run-Splunk-as-root-or-non-root-user/m-p/143571#M4395</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2014-08-25T13:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: Should we run Splunk as root or non-root user?</title>
      <link>https://community.splunk.com/t5/Security/Should-we-run-Splunk-as-root-or-non-root-user/m-p/143572#M4396</link>
      <description>&lt;P&gt;Great topic. I'd love to see more details in the documentation on best security practices for collection methods. Maybe a matrix?&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;syslog - Great for many network devices, however doesn't usually work for Webservers/App Servers which don't write out in the syslog format on Unix&lt;/LI&gt;
&lt;LI&gt;Running as root (security implications)&lt;/LI&gt;
&lt;LI&gt;Making logs world readable (security implications)&lt;/LI&gt;
&lt;LI&gt;Add Splunk to a group which has read permissions to logs (My first choice, however there is usually a limit of 16 groups per Unix ID and sometimes an entprise may have hundreds of groups that log files are owned by)&lt;/LI&gt;
&lt;LI&gt;Unix ACLs - May be a great alternative, however how difficult are they to manage?&lt;/LI&gt;
&lt;LI&gt;Mounting logs remotely?&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 25 Aug 2014 14:18:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Should-we-run-Splunk-as-root-or-non-root-user/m-p/143572#M4396</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2014-08-25T14:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: Should we run Splunk as root or non-root user?</title>
      <link>https://community.splunk.com/t5/Security/Should-we-run-Splunk-as-root-or-non-root-user/m-p/143573#M4397</link>
      <description>&lt;P&gt;&amp;gt; Splunk recommends that you don't run as root. &lt;/P&gt;

&lt;P&gt;I'm looking for a citation in the online docs, but not finding any specific recommendation. A recommendation from Splunk would be helpful in forming or justifying our own policy. All I have found so far is &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.3/installation/RunSplunkasadifferentornon-rootuser"&gt;Run Splunk Enterprise as a different or non-root user&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2015 14:24:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Should-we-run-Splunk-as-root-or-non-root-user/m-p/143573#M4397</guid>
      <dc:creator>jspears</dc:creator>
      <dc:date>2015-05-28T14:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: Should we run Splunk as root or non-root user?</title>
      <link>https://community.splunk.com/t5/Security/Should-we-run-Splunk-as-root-or-non-root-user/m-p/537983#M12068</link>
      <description>&lt;P&gt;Here's the source from docs:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.1/Installation/RunSplunkasadifferentornon-rootuser" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.1/Installation/RunSplunkasadifferentornon-rootuser&lt;/A&gt;&lt;/P&gt;&lt;P&gt;In section "Run Splunk Enterprise as a different or non-root user":&lt;/P&gt;&lt;P&gt;It says:&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;On *nix based systems, you can run Splunk Enterprise as a user other than root. This is a Splunk best practice and &lt;STRONG&gt;you should configure&lt;/STRONG&gt; your systems to run the software &lt;STRONG&gt;as a non-root&lt;/STRONG&gt; user where possible.&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jan 2021 16:32:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Should-we-run-Splunk-as-root-or-non-root-user/m-p/537983#M12068</guid>
      <dc:creator>highsplunker</dc:creator>
      <dc:date>2021-01-30T16:32:38Z</dc:date>
    </item>
  </channel>
</rss>

