Security

Is it possible to admin Splunk instance without logon to the OS splunk user?

damucka
Builder

Hello,

I have an issue with the security of the Splunk installation. Actually it is not about Splunk itself - after each security audit in my company, the OS user Splunk gets turned into the no shell, which means I am not able to switch to it using the su command. 

Is it possible at all to run the Splunk instance on Linux without the logon access to the "splunk" OS user?

Surely one could turn the Splunk into the service version, but when I think about creating/changing the configuration files .. they all have to have proper access rights - the easiest is to do it as a "splunk". When operating it as a root, sooner or later there will be an issues with that I would say.

Or is my understanding completely wrong?

Kind Regards,

Kamil 

Labels (1)
0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

To some extent it depends on your environment. With a simple all-in-one installation you might do with just restarting the process with systemctl. With a clustered installation, to be honest, I don't think I would be able to effectively use it without being able to call splunk to - for example - validate configuration bundle.

But remember that even though the account might have nologin as shell, or something like that, you can always specify your own shell with su 🙂

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Can you explain to your company's security people that the splunk account is necessary for managing Splunk and that the account needs a shell?  Yes, you can use root, but there are bigger security risks to doing that as well as the issues you mentioned.

---
If this reply helps you, Karma would be appreciated.

PickleRick
SplunkTrust
SplunkTrust

To some extent it depends on your environment. With a simple all-in-one installation you might do with just restarting the process with systemctl. With a clustered installation, to be honest, I don't think I would be able to effectively use it without being able to call splunk to - for example - validate configuration bundle.

But remember that even though the account might have nologin as shell, or something like that, you can always specify your own shell with su 🙂

damucka
Builder

@PickleRick 

Honestly, your last tip made my day 🙂

Regards,

Kamil

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...