Deployment Architecture

Can we add a dedicated search head to give admin rights?

splunkreal
Motivator

Hello,

we have 3 SHC, could it be possible to add 1 SH dedicated to a special team and give admin rights only to this last one?

Thanks.

* If this helps, please upvote or accept solution if it solved *
Labels (1)
0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

You should simply install a separate SH using the same indexer(s).

Of course it would be managed completely separately from the SHC.

View solution in original post

PickleRick
SplunkTrust
SplunkTrust

You should simply install a separate SH using the same indexer(s).

Of course it would be managed completely separately from the SHC.

splunkreal
Motivator

Is it possible however this team adds then can_delete or delete_by_keyword capability and may be able to delete data on clustered indexers? Thanks.

* If this helps, please upvote or accept solution if it solved *
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Yes. Any permissions for actions called by users from SH are defined on that SH. You simply "pair" SH(C) with IDX(C) and the IDX has no concept of the end user, its identity and such. It's the SH that decides who can do what so if you give someone admin rights on SH, he can effectively do anything with your data.

Separating SH(C)'s makes sense for purposes of isolating search-time artifacts, KV-stores, managing saved searches and so on.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @splunkreal,

yes it's possibile but it isn't a good idea!

Ciao.

Giuseppe

splunkreal
Motivator

so that's the risk 😉

* If this helps, please upvote or accept solution if it solved *
0 Karma

isoutamo
SplunkTrust
SplunkTrust

That’s probably the biggest issue, as they had admin rights then they can do anything to all data what you have on your indexers. You cannot e.g. disable access to any indexes as they can add access to those as they want.

0 Karma

splunkreal
Motivator

Yes this looks good solution, thanks.

* If this helps, please upvote or accept solution if it solved *
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @splunkreal,

if you have a Search Head Cluster you have the same rights in all the components.

if you have not clustered SHs, you can give different rigths to the configurated roles.

Anyway, you can give different grants to different groups (or roles).

Ciao.

Giuseppe

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

Ready to make your IT operations smarter and more efficient? Discover how to automate Splunk alerts with Red ...