All Apps and Add-ons

How to allow non-root user to check the search head cluster status?

vin02
Path Finder

There is a requirement to allow non-root user to query the cluster status by executing clustat command. But the non-root users are not allowed to execute this command. How to implement the same?

0 Karma

koshyk
Super Champion

What we have done is , on the cluster Master (or server which holds the DMC or Monitoring Console), we have copied the searches and created a new app with such dashboards which are meant for users.

So in step by step
- create an App MY_stats_app
- Put dashboards, searches, useful things into this app
- Create role for such users who need to access this app (eg MY_ROLE_stats)
- Allow access to this app ONLY for the role

This will make your administration/management very flexible and can allow team-leads/groups/users to access this specific app with centralised management (whereby SH cluster status is just one dashboard or panel)

0 Karma

vin02
Path Finder

I have created one non root user 'splunk'. What will be the command to check the search head cluster status using splunk user?

0 Karma

koshyk
Super Champion

the above steps are in Splunk UI. So please log to UI and do the Monitoring Console steps

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...