Security

Application Without Authentication

srussellnpr
Explorer

Could I create an application in splunk that requires no authentication? Since splunk already lives on our intranet, I'd like to give users access to dashboards without requiring them to log in.

Tags (1)

southeringtonp
Motivator

Yes. There are a few things you can do.

Here's an example site (from the guys who do the SplunkTalk podcast):
     http://bit.ly/splunktalkanalytics

Take a look at this video blog post:
     http://blogs.splunk.com/2010/09/27/video-glimpse-into-splunktalk-podcast-analytics-insecure-login-da...


The gist is that you can use "insecure" authentication, and embed login credentials into the URL. Then, create a dedicated role for that user, giving it access to on the indexes, search commands, etc. that it actually needs. Maybe even assign a search filter. Also, create a dedicated search app, with just the dashboards you need, and make that the default for the user. Using a separate, stripped-down search head can also help limit your attack surface.

If you want to use always-on displays, the timeouts can be a problem as well, so see this thread:
     http://answers.splunk.com/questions/7233/user-specific-browser-session-timeout

Remember the common tradeoffs between security and usability apply, so doing this of course involves a bit of additional risk. Provided you're ok with that, this should get you started.

srussellnpr
Explorer

You're awesome southeringtonp!

0 Karma

woodcock
Esteemed Legend

The first 2 links are dead; is there an archive anywhere?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

How Edge Processor's Durable Queue Works

Edge Processor sits in one of the most consequential places in any Splunk pipeline: between your data sources ...