<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Permissions in cluster in Security</title>
    <link>https://community.splunk.com/t5/Security/Permissions-in-cluster/m-p/294807#M7887</link>
    <description>&lt;P&gt;You need to configure search head so it will point to cluster master and search data from Indexer cluster. Please refer &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.1/Indexer/Configuresearchheadwithserverconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.1/Indexer/Configuresearchheadwithserverconf&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 24 Nov 2017 08:31:39 GMT</pubDate>
    <dc:creator>harsmarvania57</dc:creator>
    <dc:date>2017-11-24T08:31:39Z</dc:date>
    <item>
      <title>Permissions in cluster</title>
      <link>https://community.splunk.com/t5/Security/Permissions-in-cluster/m-p/294802#M7882</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;from my old standalone Splunk system I'll migrate to an Splunk Cluster with the following Systems;&lt;BR /&gt;
- 1 Searchhead&lt;BR /&gt;
- 1 Masternode&lt;BR /&gt;
- 3 Peernodes&lt;/P&gt;

&lt;P&gt;In my old system I've multiple roles with different access permissions on base of indices. In the role configuration I can simple activate permission on an index or not. &lt;/P&gt;

&lt;P&gt;In the new cluster the indices will been configured at the master node within "../etc/master-apps/*".&lt;/P&gt;

&lt;P&gt;Here are my questions:&lt;BR /&gt;
- Have I anywhere in Splunk an graphical interface to manage the indizes which will been replicated? Under Settings -&amp;gt; Indices I can only see the local indices but not the replicated ones. &lt;BR /&gt;
- The permissions for the cluster will be configured at the searchhead, correct? If I must now configure a new role which have for example only permissions to the index "cluster_index_1" I can not simple activate the index in the role configuration because my system does not see all the available indices. Is it neccessary to create at the searchhead all the indices which are available in the cluster so that I can choose them in the role configuration? &lt;/P&gt;

&lt;P&gt;For me the configuration of an Splunk cluster is currently not a straight forward thing. There are different locations where I must configure something. &lt;/P&gt;

&lt;P&gt;Thanks and best regards&lt;BR /&gt;
seilemor&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:52:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Permissions-in-cluster/m-p/294802#M7882</guid>
      <dc:creator>seilemor</dc:creator>
      <dc:date>2020-09-29T16:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions in cluster</title>
      <link>https://community.splunk.com/t5/Security/Permissions-in-cluster/m-p/294803#M7883</link>
      <description>&lt;P&gt;Hi @seilemor,&lt;/P&gt;

&lt;P&gt;1.) You mentioned that you are not able to see replicated indices Under Settings -&amp;gt; Indices, can you please define "replicated indices"  and on which splunk server are you checking this?&lt;BR /&gt;
2.) Yes, you can just assign index to existing role or create new role on search head with require indexes but as you mentioned that you are not able to see all indexes while configuring role, so can you please let us know how your search head is connected with indexers ?  You need to configure search head so it will point to cluster master and search data from Indexer cluster. Please refer &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.1/Indexer/Configuresearchheadwithserverconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.1/Indexer/Configuresearchheadwithserverconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;EDIT: 1.) I have provided wrong link to integrate standalone search head with Indexer cluster.&lt;BR /&gt;
2.) Provided correct URL to configure search head with indexer lcuster.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 11:51:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Permissions-in-cluster/m-p/294803#M7883</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2017-11-23T11:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions in cluster</title>
      <link>https://community.splunk.com/t5/Security/Permissions-in-cluster/m-p/294804#M7884</link>
      <description>&lt;P&gt;Hi and thanks for the quick answer.&lt;/P&gt;

&lt;P&gt;With an replicated index I mean these Indices which will been mirrored on my peernodes. I can see these indices within "Settings -&amp;gt; Distributed Environment -&amp;gt; Indexer Clustering -&amp;gt; Indexes". I search for the indices on the masternode. &lt;/P&gt;

&lt;P&gt;Searching data from the searchhead is possible. It is only the question how can I restrict some roles and users to specific Indices which are replicated from my masternode to my peernodes. I think that this is only possible if I also create the Indices on my searchhead (only that they are available and can be choosen in the role configuration, for example with a size of 1MB because I only use them to control the permissions. ).&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 12:08:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Permissions-in-cluster/m-p/294804#M7884</guid>
      <dc:creator>seilemor</dc:creator>
      <dc:date>2017-11-23T12:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions in cluster</title>
      <link>https://community.splunk.com/t5/Security/Permissions-in-cluster/m-p/294805#M7885</link>
      <description>&lt;P&gt;1.) Indexes which are showing on Cluster Master &lt;CODE&gt;Settings -&amp;gt; Distributed Environment -&amp;gt; Indexer Clustering -&amp;gt; Indexes&lt;/CODE&gt; those indexes are available on Indexers and if you go to &lt;CODE&gt;Settings -&amp;gt; Indexes&lt;/CODE&gt;on Cluster Master you will able to see only local indexes which are available on Cluster Master.&lt;/P&gt;

&lt;P&gt;2.) Why you are applying role configuration from Cluster Master to Indexer ? Role configuration is only require on Search Head and when search head tries to search any data from indexers it will pass knowledge bundle which contains roles configuration and many other settings so you do not need to push role configuration from Cluster Master to Indexers.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 15:07:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Permissions-in-cluster/m-p/294805#M7885</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2017-11-23T15:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions in cluster</title>
      <link>https://community.splunk.com/t5/Security/Permissions-in-cluster/m-p/294806#M7886</link>
      <description>&lt;P&gt;I don't want apply role configuration from the cluster master to my indexer.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;The requirement:&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;
I want to have a &lt;CODE&gt;Role A&lt;/CODE&gt; and &lt;CODE&gt;Role B&lt;/CODE&gt;. &lt;CODE&gt;Role A&lt;/CODE&gt; have permissions to the &lt;CODE&gt;Index 123&lt;/CODE&gt; and &lt;CODE&gt;Role B&lt;/CODE&gt; should have permission for the &lt;CODE&gt;Index ABC&lt;/CODE&gt;. Both roles should not have permission to the other index.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Current configuration:&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;
On my master node I have configured within &lt;CODE&gt;$SPLUNKHOME/etc/master-apps/_cluster/local/indexes.conf&lt;/CODE&gt; the neccessary &lt;CODE&gt;Index 123&lt;/CODE&gt; and &lt;CODE&gt;Index ABC&lt;/CODE&gt;. Both configurations have the configuration &lt;CODE&gt;repFactor = auto&lt;/CODE&gt; so that these index configuration will be replicated to the peer nodes. On my peer nodes I can see the configuration regarding the indices within &lt;CODE&gt;Settings -&amp;gt; Indexes&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;To finalize my configuration I must now configure the roles at my searchhead regarding the described requirements.&lt;BR /&gt;
&lt;CODE&gt;Role A = Index 123&lt;/CODE&gt;&lt;BR /&gt;
&lt;CODE&gt;Role B = Index ABC&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;The problem:&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;
Within my role configuration on my searchhead I don't see the available indices. That means that I can not choose within the role configuration for which index the role should been permitted. &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Question:&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;
How can I handle this problem?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2017 07:11:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Permissions-in-cluster/m-p/294806#M7886</guid>
      <dc:creator>seilemor</dc:creator>
      <dc:date>2017-11-24T07:11:52Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions in cluster</title>
      <link>https://community.splunk.com/t5/Security/Permissions-in-cluster/m-p/294807#M7887</link>
      <description>&lt;P&gt;You need to configure search head so it will point to cluster master and search data from Indexer cluster. Please refer &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.1/Indexer/Configuresearchheadwithserverconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.1/Indexer/Configuresearchheadwithserverconf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2017 08:31:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Permissions-in-cluster/m-p/294807#M7887</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2017-11-24T08:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions in cluster</title>
      <link>https://community.splunk.com/t5/Security/Permissions-in-cluster/m-p/294808#M7888</link>
      <description>&lt;P&gt;Searching the data is not the problem. From the searchhead I can search all the data which are available on the peer nodes. &lt;/P&gt;

&lt;P&gt;The problem is the permission of the users. I want that the user can only search within some dedicated indices. The user should not have the ability to search through all data which are available on the peer nodes.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2017 09:04:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Permissions-in-cluster/m-p/294808#M7888</guid>
      <dc:creator>seilemor</dc:creator>
      <dc:date>2017-11-24T09:04:56Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions in cluster</title>
      <link>https://community.splunk.com/t5/Security/Permissions-in-cluster/m-p/294809#M7889</link>
      <description>&lt;P&gt;ok, so can you please let me know when you try to configure role on Search Head are you able to see any indexes which are present on Indexers ? If not then can you please try to create blank &lt;CODE&gt;Index 123&lt;/CODE&gt; on search head and then try again to configure role.&lt;/P&gt;

&lt;P&gt;EDIT: If you are running Splunk 7 then you are hitting bug ref link &lt;A href="https://answers.splunk.com/answers/583581/indexes-are-not-available-to-select-from-available-1.html"&gt;https://answers.splunk.com/answers/583581/indexes-are-not-available-to-select-from-available-1.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2017 09:10:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Permissions-in-cluster/m-p/294809#M7889</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2017-11-24T09:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions in cluster</title>
      <link>https://community.splunk.com/t5/Security/Permissions-in-cluster/m-p/294810#M7890</link>
      <description>&lt;P&gt;Thats it. Thanks. I've the same issue as described in the linked question. I've also tested what happen if I manualy create the index as described from you. This will work for me. In my first question of this thread I only wanted to know if this is normal or if I have an issue in my configuration. Now I know that it is an bug. &lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2017 09:25:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Permissions-in-cluster/m-p/294810#M7890</guid>
      <dc:creator>seilemor</dc:creator>
      <dc:date>2017-11-24T09:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: Permissions in cluster</title>
      <link>https://community.splunk.com/t5/Security/Permissions-in-cluster/m-p/294811#M7891</link>
      <description>&lt;P&gt;Thanks, I have converted my comment to answer, if you are satisfied with the answer then please accept as answer and upvote.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2017 09:27:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Permissions-in-cluster/m-p/294811#M7891</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2017-11-24T09:27:53Z</dc:date>
    </item>
  </channel>
</rss>

