All Apps and Add-ons

Cisco IronPort - Splunk Integration (SCP Issue)

socespap
Explorer

Hi,

I am trying to integrate a Cisco ESA into splunk and I realized that I have constraints regarding to privileges related to the user that I am using. In this brief test I have been using 'root' but doesn't work properly

type=USER_AUTH msg=audit(1548086500.719:6438): pid=31410 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey acct="root" exe="/usr/sbin/sshd" hostname=? addr=10.150.0.11 terminal=ssh res=failed'

SSH folder was configures as 700 privileges, and authorized_keys file as 644.

Any idea about this issue?

Sincerely,

Vitor Leitao

Tags (1)
0 Karma

hcanivel_splunk
Splunk Employee
Splunk Employee

First of all, you should never be using root to SSH/SCP anything, especially if it's publicly facing infrastructure.
Secondly, can you even verify if SSH for root user is enabled? By default, your sshd should have that disabled.
Thirdly, what are your debug logs for both client and server? I would presume testing against root user is disabled for SSH access, but would like to see the actual reason for failure.

0 Karma

socespap
Explorer

Just to add the following log

Mon Jan 21 16:00:04 2019 Info: Appliance:xxxx, Interaction mode: SSH Client, User: *****, Dest IP: X.X.X.X:22, Event: SCP failed. Reason - Permission denied (publickey,password). lost connection
eventtype = cisco-security-events eventtype = err0r error host = XXXX source = /opt/splunk/etc/apps/Splunk_TA_cisco-esa/local/[email protected] sourcetype = cisco:esa:authentication

0 Karma

spodda01da
Path Finder

Hi socespap, Did you get it configured, I am too looking to configure via SCP but facing some challenges. Please do let me know how did you fix it.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...