Installation

Can I Install Splunk Enterprise as a non-root user, run Splunk Enterprise as a non-root user, as well as listen directly on a port below 1024?

wellchai0914
New Member

Can I Install Splunk Enterprise as a non-root user, run Splunk Enterprise as a non-root user, as well as listen directly on a port below 1024?

Tags (1)
0 Karma

wellkitkit
Engager

May I know if I can use the setcap to solve non-root user listening to a port below 1024 as below

setcap cap_net_bind_service=ep /opt/splunk/bin/splunkd

gjanders
SplunkTrust
SplunkTrust

From a Unix OS point of view no, you cannot be non-root and listen to a port below 1024

You can use various tricks such as port re-direction to work around this, but a better question is what problem are you trying to solve?
If you need a UDP or TCP listener on a port below 1024 you might want to have a look at syslogNG, I have a post on it here

0 Karma
Get Updates on the Splunk Community!

BSides Splunk 2022 - The Call for Papers is now Open!

TLDR; Main Site: https://bsidessplunk.com CFP Site: https://bsidessplunk.com/cfp CFP Opens: December 15th, ...

Sending Metrics to Splunk Enterprise With the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...