<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configure Splunk Forwarder only with admin account in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Configure-Splunk-Forwarder-only-with-admin-account/m-p/327449#M12262</link>
    <description>&lt;P&gt;Hi splunkTest13,&lt;BR /&gt;
just few additional information:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;what's the operative system you're using?&lt;/LI&gt;
&lt;LI&gt;are you speaking of an operative system user or a Splunk User?&lt;/LI&gt;
&lt;LI&gt;what's the user you used for installation and Splunk processes running?&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;It's possible to install Forwarders using a non admin user, see:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Installation/RunSplunkasadifferentornon-rootuser"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Installation/RunSplunkasadifferentornon-rootuser&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Installation/ChoosetheuserSplunkshouldrunas"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Installation/ChoosetheuserSplunkshouldrunas&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Fri, 02 Mar 2018 15:35:10 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2018-03-02T15:35:10Z</dc:date>
    <item>
      <title>Configure Splunk Forwarder only with admin account</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Configure-Splunk-Forwarder-only-with-admin-account/m-p/327448#M12261</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;I'm running Splunk free trial 7.0.1. &lt;BR /&gt;
I need to create an user to configure my forwarder, but not with the admin account. &lt;BR /&gt;
I try to understand if it's about roles or capacity. But when i create an user, and give it to him admin role, i can't configure my forwarder, login failed. &lt;/P&gt;

&lt;P&gt;Another thing is that i already change a couple of time password of admin account. And when i configure my forwarder, old password work. Strange no ? I try to read configuration files, to see if old password were stored, but nothing. &lt;/P&gt;

&lt;P&gt;Thanks in advance, &lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 09:41:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Configure-Splunk-Forwarder-only-with-admin-account/m-p/327448#M12261</guid>
      <dc:creator>splunkTest13</dc:creator>
      <dc:date>2018-03-02T09:41:09Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Splunk Forwarder only with admin account</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Configure-Splunk-Forwarder-only-with-admin-account/m-p/327449#M12262</link>
      <description>&lt;P&gt;Hi splunkTest13,&lt;BR /&gt;
just few additional information:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;what's the operative system you're using?&lt;/LI&gt;
&lt;LI&gt;are you speaking of an operative system user or a Splunk User?&lt;/LI&gt;
&lt;LI&gt;what's the user you used for installation and Splunk processes running?&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;It's possible to install Forwarders using a non admin user, see:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Installation/RunSplunkasadifferentornon-rootuser"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Installation/RunSplunkasadifferentornon-rootuser&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Installation/ChoosetheuserSplunkshouldrunas"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Installation/ChoosetheuserSplunkshouldrunas&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 15:35:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Configure-Splunk-Forwarder-only-with-admin-account/m-p/327449#M12262</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2018-03-02T15:35:10Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Splunk Forwarder only with admin account</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Configure-Splunk-Forwarder-only-with-admin-account/m-p/327450#M12263</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;Sorry sorry ... I was really busy on another subject. &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;So, the operating system is RedHat Linux &lt;/LI&gt;
&lt;LI&gt;I speak about a Splunk User who will had the same role of Splunk Admin for connecting remote forwarder to the instance of Splunk&lt;/LI&gt;
&lt;LI&gt;I use actually the default administrator user --&amp;gt; admin:changeme &lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;But I want to create, like admin, an user like user_forwarder  so that when i configure my forwarder on the remote machine, i don't give to technician the credentials of administrator of Splunk. &lt;/P&gt;

&lt;P&gt;Thanks a lot. &lt;/P&gt;

&lt;P&gt;Regards, &lt;/P&gt;

&lt;P&gt;Juliette&lt;/P&gt;</description>
      <pubDate>Tue, 13 Mar 2018 10:18:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Configure-Splunk-Forwarder-only-with-admin-account/m-p/327450#M12263</guid>
      <dc:creator>splunkTest13</dc:creator>
      <dc:date>2018-03-13T10:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Splunk Forwarder only with admin account</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Configure-Splunk-Forwarder-only-with-admin-account/m-p/327451#M12264</link>
      <description>&lt;P&gt;Hi Juliette,&lt;BR /&gt;
are you speaking about a Splunk user on Forwarder, correct?&lt;/P&gt;

&lt;P&gt;Forwarders are usually managed using a Deployment Server (see &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.2/Updating/Configuredeploymentclients"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.2/Updating/Configuredeploymentclients&lt;/A&gt; )&lt;BR /&gt;
in few words on forwarder run the following commands&lt;BR /&gt;
    splunk set deploy-poll &lt;IP_ADDRESS&gt;:&lt;MANAGEMENT_PORT&gt;&lt;BR /&gt;
    splunk restart&lt;BR /&gt;
and then manage its configurations on your Splunk Enterprise (if you have an All-in-one installation and few forwarders), or on your Deployment Server (if you have many forwarders) deploying Technical Add-ons (see the below url).&lt;/MANAGEMENT_PORT&gt;&lt;/IP_ADDRESS&gt;&lt;/P&gt;

&lt;P&gt;Otherwise, if you're making a test or a PoC, you can manually configure forwarders using admin user: there are no reasons to use a different Splunk user (if possible: I never tried!).&lt;BR /&gt;
Eventually, you could change the default admin password:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunk edit user admin -password "new_password" -auth admin:current_password
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Anyway you can have different passwords between Splunk Enterprise and Forwarders.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 13 Mar 2018 12:07:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Configure-Splunk-Forwarder-only-with-admin-account/m-p/327451#M12264</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2018-03-13T12:07:02Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Splunk Forwarder only with admin account</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Configure-Splunk-Forwarder-only-with-admin-account/m-p/327452#M12265</link>
      <description>&lt;P&gt;Hi, thanks again for your answer. &lt;BR /&gt;
Sorry, but just to be clear : Is that mandatory to use deployment server ? &lt;BR /&gt;
Because currently, I have 3 forwarders on 3 remote machine. As you say, it was a PoC but it's become a pilote and for security reason the user allowing connection when I do : &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[host /]$ sudo /opt/splunkforwarder/bin/splunk add forward-server ip:port -auth admin:changeme
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;in my remote machine is my admin account.&lt;/P&gt;

&lt;P&gt;If i create in Splunk web interface an user with the same role as admin (all the roles), and i try again on my remote server to add forwarder server :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[host /]$ sudo /opt/splunkforwarder/bin/splunk add forward-server ip:port -auth juliette:juliette
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Then login failed. While nothing is different between admin user and juliette user. &lt;/P&gt;

&lt;P&gt;I'm not sure that i explain well my problem, maybe it's my english or maybe i don't understand something in splunk configurations. &lt;/P&gt;

&lt;P&gt;Another time, &lt;/P&gt;

&lt;P&gt;Thanks a lot. &lt;BR /&gt;
Regards,&lt;BR /&gt;
Juliette&lt;/P&gt;</description>
      <pubDate>Tue, 13 Mar 2018 14:44:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Configure-Splunk-Forwarder-only-with-admin-account/m-p/327452#M12265</guid>
      <dc:creator>splunkTest13</dc:creator>
      <dc:date>2018-03-13T14:44:42Z</dc:date>
    </item>
  </channel>
</rss>

