All Apps and Add-ons

Cisco IronPort - Splunk Integration (SCP Issue)

socespap
Explorer

Hi,

I am trying to integrate a Cisco ESA into splunk and I realized that I have constraints regarding to privileges related to the user that I am using. In this brief test I have been using 'root' but doesn't work properly

type=USER_AUTH msg=audit(1548086500.719:6438): pid=31410 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey acct="root" exe="/usr/sbin/sshd" hostname=? addr=10.150.0.11 terminal=ssh res=failed'

SSH folder was configures as 700 privileges, and authorized_keys file as 644.

Any idea about this issue?

Sincerely,

Vitor Leitao

Tags (1)
0 Karma

hcanivel_splunk
Splunk Employee
Splunk Employee

First of all, you should never be using root to SSH/SCP anything, especially if it's publicly facing infrastructure.
Secondly, can you even verify if SSH for root user is enabled? By default, your sshd should have that disabled.
Thirdly, what are your debug logs for both client and server? I would presume testing against root user is disabled for SSH access, but would like to see the actual reason for failure.

0 Karma

socespap
Explorer

Just to add the following log

Mon Jan 21 16:00:04 2019 Info: Appliance:xxxx, Interaction mode: SSH Client, User: *****, Dest IP: X.X.X.X:22, Event: SCP failed. Reason - Permission denied (publickey,password). lost connection
eventtype = cisco-security-events eventtype = err0r error host = XXXX source = /opt/splunk/etc/apps/Splunk_TA_cisco-esa/local/[email protected] sourcetype = cisco:esa:authentication

0 Karma

spodda01da
Path Finder

Hi socespap, Did you get it configured, I am too looking to configure via SCP but facing some challenges. Please do let me know how did you fix it.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...