Installation

Can I Install Splunk Enterprise as a non-root user, run Splunk Enterprise as a non-root user, as well as listen directly on a port below 1024?

wellchai0914
New Member

Can I Install Splunk Enterprise as a non-root user, run Splunk Enterprise as a non-root user, as well as listen directly on a port below 1024?

Tags (1)
0 Karma

wellkitkit
Engager

May I know if I can use the setcap to solve non-root user listening to a port below 1024 as below

setcap cap_net_bind_service=ep /opt/splunk/bin/splunkd

gjanders
SplunkTrust
SplunkTrust

From a Unix OS point of view no, you cannot be non-root and listen to a port below 1024

You can use various tricks such as port re-direction to work around this, but a better question is what problem are you trying to solve?
If you need a UDP or TCP listener on a port below 1024 you might want to have a look at syslogNG, I have a post on it here

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...