Deployment Architecture

Permissions on CLI to execute splunk add monitor

dchang
New Member

Hi, We deploy forwarders to provide data to Splunk indexers. Whom is permitted to run the command "splunk add monitor"? Is it only the splunk user that installed the agent/forwarder?

If I wanted to permit others to add new monitors to the splunk forwarder can I do so?

Thanks, Dennis

0 Karma

dwaddle
SplunkTrust
SplunkTrust

To use the CLI command you need a Splunk login (not an operating system login) that has the Splunk admin role. How this nets out depends on some things - you can configure LDAP authentication (even for your forwarders) and let them centrally authenticate / authorize that way. Or, you can use the default admin account and whatever password you set for it. You could also add a Splunk user just for this purpose.

Alternately, splunk add monitor will eventually end up changing an inputs.conf config file. You could configure filesystem permissions to allow others to access this file, and they could edit it as necessary to add new monitor inputs.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...