<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Enterprise Security: How to secure part of the _audit index? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-secure-part-of-the-audit-index/m-p/429890#M5571</link>
    <description>&lt;P&gt;Ahhhh, crap. Totally forgot about the indexer logs that will contain the searches ran there as well, ugh. Okay sounds like I'll need to create some search term restrictions to get a semblance of security around that data.&lt;/P&gt;

&lt;P&gt;Do you think it is sufficient to do something like this??&lt;BR /&gt;
    NOT (user=123456 OR user=abcdefg)&lt;/P&gt;

&lt;P&gt;I'll know who the security people are so building that restriction will be pretty easy. Heck, if I want to get fancy I can likely resolve the security people by role and gen a lookup table to use as the restriction.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Jun 2019 13:21:57 GMT</pubDate>
    <dc:creator>tjago11</dc:creator>
    <dc:date>2019-06-21T13:21:57Z</dc:date>
    <item>
      <title>Splunk Enterprise Security: How to secure part of the _audit index?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-secure-part-of-the-audit-index/m-p/429887#M5568</link>
      <description>&lt;P&gt;We have Enterprise Security installed for a specific Search Head and would like the _audit logs in a different location than the main Search Heads. &lt;BR /&gt;
The ES SH is used for doing security investigations and we do not want the searches executed readable by the masses. &lt;BR /&gt;
However, we don't want to lock down everything in _audit.&lt;/P&gt;

&lt;P&gt;I'd think the simplest thing to do is have the _audit logs for that one SH sent to a different index?? &lt;BR /&gt;
Is that even possible??&lt;BR /&gt;
Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 12:34:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-secure-part-of-the-audit-index/m-p/429887#M5568</guid>
      <dc:creator>tjago11</dc:creator>
      <dc:date>2019-06-20T12:34:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: How to secure part of the _audit index?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-secure-part-of-the-audit-index/m-p/429888#M5569</link>
      <description>&lt;P&gt;Searches run by users are also visible in _internal so securing _audit is not enough.  Consider not forwarding _internal and _audit to your indexers (keep them local).&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 12:47:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-secure-part-of-the-audit-index/m-p/429888#M5569</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-06-20T12:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: How to secure part of the _audit index?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-secure-part-of-the-audit-index/m-p/429889#M5570</link>
      <description>&lt;P&gt;Hi @tjago11 ,&lt;/P&gt;

&lt;P&gt;As @richgalloway mentioned, securing _audit will not be enough.  You would also have to secure _internal.&lt;/P&gt;

&lt;P&gt;Even if you follow his recommendation to not forward the &lt;EM&gt;internal &amp;amp; _audit logs from the ES search head, the indexers themselves will store a copy of the searches run in _THEIR&lt;/EM&gt; _internal Splunk logs.&lt;/P&gt;

&lt;P&gt;Other than completely locking down _internal &amp;amp; _audit, there is no easy way to do this.&lt;/P&gt;

&lt;P&gt;Options to consider might be:&lt;BR /&gt;
- Search restrictions&lt;BR /&gt;
- Scripted authentication.  Using scripted authentication, you can create a level of granularity with permissions and search restrictions that prevent people from seeing certain types of data (ie: logs from _internal &amp;amp; _audit on the ES host AND the _internal logs on indexers that pertain to searches from ES hosts).  This is complicated and not easy to setup, but it is a way to accomplish what you want to do.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 19:08:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-secure-part-of-the-audit-index/m-p/429889#M5570</guid>
      <dc:creator>jnudell_2</dc:creator>
      <dc:date>2019-06-20T19:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: How to secure part of the _audit index?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-secure-part-of-the-audit-index/m-p/429890#M5571</link>
      <description>&lt;P&gt;Ahhhh, crap. Totally forgot about the indexer logs that will contain the searches ran there as well, ugh. Okay sounds like I'll need to create some search term restrictions to get a semblance of security around that data.&lt;/P&gt;

&lt;P&gt;Do you think it is sufficient to do something like this??&lt;BR /&gt;
    NOT (user=123456 OR user=abcdefg)&lt;/P&gt;

&lt;P&gt;I'll know who the security people are so building that restriction will be pretty easy. Heck, if I want to get fancy I can likely resolve the security people by role and gen a lookup table to use as the restriction.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 13:21:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-secure-part-of-the-audit-index/m-p/429890#M5571</guid>
      <dc:creator>tjago11</dc:creator>
      <dc:date>2019-06-21T13:21:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: How to secure part of the _audit index?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-secure-part-of-the-audit-index/m-p/429891#M5572</link>
      <description>&lt;P&gt;Just confirmed that if I limit the results by the user, the search data does not come back. Did a search with a guid and then went to the internal indexes to see all the places it showed up. When I add in the user restriction it finds nothing, which is good.&lt;BR /&gt;
    index=_* "ec840050-a53f-4b0e-af5a-5f0678bfbcb5" user!=123456&lt;/P&gt;

&lt;P&gt;Pretty sure this will work, thanks for the help.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 13:28:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-How-to-secure-part-of-the-audit-index/m-p/429891#M5572</guid>
      <dc:creator>tjago11</dc:creator>
      <dc:date>2019-06-21T13:28:02Z</dc:date>
    </item>
  </channel>
</rss>

