Deployment Architecture

how to push user account from master/deployment node to SHC members

dhavamanis
Builder

Need your help!,

Can you please tell us, how to push user account from master/deployment node to SHC members and etc/system/local config. We are pushing apps and users folder from etc/shcluster/ using below, but we could see any option to use etc/passwd file to SHC members. also there is no option to push the standalone search head etc/system/local directory config.

./splunk apply shcluster-bundle --answer-yes -target https://1.13.2.1:8089 -auth admin:changeme

Tags (1)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

If you're using Splunk's built-in authentication then you will have to add every user to each cluster member:

http://docs.splunk.com/Documentation/Splunk/6.2.3/DistSearch/AdduserstotheSHC#Use_Splunk_Enterprise_...

martin_mueller
SplunkTrust
SplunkTrust

Great. If that answers your question then please mark the answer as accepted.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

As the path implies, those settings are local to a system. If you want to push them to the cluster you should package them in an app, or configure the settings on each member.

0 Karma

dhavamanis
Builder

Thank you so much for the details.

0 Karma

dhavamanis
Builder

thanks, We are using external SSO authentication, but user permissions are stored in Splunk. Can you please tell us, how to copy the standalone etc/system/local/ (web.conf, transforms.conf..etc) files to SHC nodes?.

0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...