All Apps and Add-ons

Cisco IronPort - Splunk Integration (SCP Issue)

socespap
Explorer

Hi,

I am trying to integrate a Cisco ESA into splunk and I realized that I have constraints regarding to privileges related to the user that I am using. In this brief test I have been using 'root' but doesn't work properly

type=USER_AUTH msg=audit(1548086500.719:6438): pid=31410 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey acct="root" exe="/usr/sbin/sshd" hostname=? addr=10.150.0.11 terminal=ssh res=failed'

SSH folder was configures as 700 privileges, and authorized_keys file as 644.

Any idea about this issue?

Sincerely,

Vitor Leitao

Tags (1)
0 Karma

hcanivel_splunk
Splunk Employee
Splunk Employee

First of all, you should never be using root to SSH/SCP anything, especially if it's publicly facing infrastructure.
Secondly, can you even verify if SSH for root user is enabled? By default, your sshd should have that disabled.
Thirdly, what are your debug logs for both client and server? I would presume testing against root user is disabled for SSH access, but would like to see the actual reason for failure.

0 Karma

socespap
Explorer

Just to add the following log

Mon Jan 21 16:00:04 2019 Info: Appliance:xxxx, Interaction mode: SSH Client, User: *****, Dest IP: X.X.X.X:22, Event: SCP failed. Reason - Permission denied (publickey,password). lost connection
eventtype = cisco-security-events eventtype = err0r error host = XXXX source = /opt/splunk/etc/apps/Splunk_TA_cisco-esa/local/authentication.@20190121T160003.s sourcetype = cisco:esa:authentication

0 Karma

spodda01da
Path Finder

Hi socespap, Did you get it configured, I am too looking to configure via SCP but facing some challenges. Please do let me know how did you fix it.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...