<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Enterprise Security: &amp;quot;Search peer has the following message: Review roles for unnecessary read or write access to authorize.conf and remove access if possible.&amp;quot; in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-quot-Search-peer-has-the-following/m-p/313759#M2851</link>
    <description>&lt;P&gt;"Search peer has the following message: Review roles for unnecessary read or write access to authorize.conf and remove access if possible. Learn more"&lt;/P&gt;

&lt;P&gt;The above is the warning message I am getting after I updated the Splunk ES to 4.7.2. Could someone advice what needs to be done here.&lt;/P&gt;</description>
    <pubDate>Mon, 16 Oct 2017 17:17:55 GMT</pubDate>
    <dc:creator>10306629</dc:creator>
    <dc:date>2017-10-16T17:17:55Z</dc:date>
    <item>
      <title>Splunk Enterprise Security: "Search peer has the following message: Review roles for unnecessary read or write access to authorize.conf and remove access if possible."</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-quot-Search-peer-has-the-following/m-p/313759#M2851</link>
      <description>&lt;P&gt;"Search peer has the following message: Review roles for unnecessary read or write access to authorize.conf and remove access if possible. Learn more"&lt;/P&gt;

&lt;P&gt;The above is the warning message I am getting after I updated the Splunk ES to 4.7.2. Could someone advice what needs to be done here.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 17:17:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-quot-Search-peer-has-the-following/m-p/313759#M2851</guid>
      <dc:creator>10306629</dc:creator>
      <dc:date>2017-10-16T17:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: "Search peer has the following message: Review roles for unnecessary read or write access to authorize.conf and remove access if possible."</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-quot-Search-peer-has-the-following/m-p/313760#M2852</link>
      <description>&lt;P&gt;The Splunk has introduced number of new roles with latest ES (4.7 and above ) version.  The warning is thrown to make user aware of these changes so that he/she can reconfigure access control if required.  &lt;/P&gt;

&lt;P&gt;You can refer &lt;A href="http://docs.splunk.com/Documentation/ES/4.7.0/Install/ConfigureUsersRoles"&gt;http://docs.splunk.com/Documentation/ES/4.7.0/Install/ConfigureUsersRoles&lt;/A&gt; for more information.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 05:27:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-quot-Search-peer-has-the-following/m-p/313760#M2852</guid>
      <dc:creator>hardikJsheth</dc:creator>
      <dc:date>2017-10-17T05:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: "Search peer has the following message: Review roles for unnecessary read or write access to authorize.conf and remove access if possible."</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-quot-Search-peer-has-the-following/m-p/313761#M2853</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I had the same problem and from what I understand the explanation is as follow :&lt;BR /&gt;
- ES used to have to change right to authorize.conf but the way it was done was not ideal.&lt;BR /&gt;
- ES 4.7 migrate the old configuration to a new config which remove the original need. &lt;BR /&gt;
- the migration script has no way to know that the changes to authorize.conf where done by ES -&amp;gt; don't touch them as they could be legitimate otherwise.&lt;BR /&gt;
- ES permission checks detect the too open permission and warm about&lt;/P&gt;

&lt;P&gt;So the current solution would be to manually go on each app in metadata/local.meta , look for authorize.conf stanza and remove non admin right on it as appropriate to your env.&lt;/P&gt;

&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 20:33:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-quot-Search-peer-has-the-following/m-p/313761#M2853</guid>
      <dc:creator>maraman_splunk</dc:creator>
      <dc:date>2017-10-17T20:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: "Search peer has the following message: Review roles for unnecessary read or write access to authorize.conf and remove access if possible."</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-quot-Search-peer-has-the-following/m-p/313762#M2854</link>
      <description>&lt;P&gt;Thanks maraman, i have did that but still i am getting these message &lt;STRONG&gt;"Splunk Enterprise Security: "Search peer has the following message: Review roles for unnecessary read or write access to authorize.conf and remove access if possible."&lt;/STRONG&gt; &lt;BR /&gt;
could please suggest me any other way to do this..&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 19:18:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-quot-Search-peer-has-the-following/m-p/313762#M2854</guid>
      <dc:creator>10306629</dc:creator>
      <dc:date>2017-11-27T19:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: "Search peer has the following message: Review roles for unnecessary read or write access to authorize.conf and remove access if possible."</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-quot-Search-peer-has-the-following/m-p/313763#M2855</link>
      <description>&lt;P&gt;hello maraman even I have the same problem, the solution provided seems very appropriate. The trouble is I could see the roles admin, ess_analyst  tagged to most of the users. what are the things that still need to checked and how, please let me know.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 20:03:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-quot-Search-peer-has-the-following/m-p/313763#M2855</guid>
      <dc:creator>vicky05ssr04</dc:creator>
      <dc:date>2017-11-27T20:03:11Z</dc:date>
    </item>
  </channel>
</rss>

