Deployment Architecture

Where do I add local accounts on a Splunk 6.4 Search Head Cluster?

a212830
Champion

Hi,

If I need to add a local account on a Splunk 6.4 Search Head Cluster, where is it done, and does it replicate?

0 Karma

sloshburch
Splunk Employee
Splunk Employee

Woah woah woah. I think those posts are for before 6.4. My understanding was the in 6.4 the local user accounts were replicated without issue.

(fair warning: I haven't check the links y'all posted just yet so apologies if I'm completely off).

I'll update this post with the details when I find them. I'm guessing its all in the docs.

0 Karma

sloshburch
Splunk Employee
Splunk Employee

Glad I jumped in here. See what @MuS posted? That's correct: http://docs.splunk.com/Documentation/Splunk/6.4.0/DistSearch/AdduserstotheSHC

Specifically, this is the bad boy you're looking for:

For Splunk Enterprise built-in authentication, you can use Splunk Web or the CLI to add users and map roles. Perform the operation on any one of the cluster members. The cluster then automatically distributes the changes to all members by replicating the $SPLUNK_HOME/etc/passwd file.

a212830
Champion

Another reason to use 6.4. Awesome.

0 Karma

MuS
Legend

Yes, @SloshBurch [Splunk] I just used the wrong old link in the first post - corrected now! Thanks for pointing out this nice new feature!

0 Karma

MuS
Legend

Hi a212830,

UPDATE:

This is the link you're looking for in Splunk 6.4.0:

http://docs.splunk.com/Documentation/Splunk/6.4.0/DistSearch/AdduserstotheSHC

Add the user on any Cluster node to $SPLUNK_HOME/etc/passwd and it will be replicated in the cluster.

And here the pre Splunk 6.4.x solution:
Look at the docs http://docs.splunk.com/Documentation/Splunk/6.3.3/DistSearch/AdduserstotheSHC#Use_Splunk_Enterprise_... and pay attention to this note:

  1. Create a script that adds each user through the splunk add user CLI command.
  2. Run the script on each cluster member.

There is one answer https://answers.splunk.com/answers/181506/how-to-create-and-share-usersroles-between-search.html where you can find one solution to replicate it using rsync between all the SHC nodes.

Hope this helps ...

cheers, MuS

MuS
Legend
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...