Security
Highlighted

Search head pooling and authorize.conf

Builder

Hi,

I'm wondering how Splunk (4.3.x) deals with new roles created through the GUI. Since they're located in etc/system, I suppose you have to distribute any changes by yourself, or is there a way to automate this?

Highlighted

Re: Search head pooling and authorize.conf

SplunkTrust
SplunkTrust

I'm in a similar situation, but on 5.0.1. I'd love to see the solution as well.

Highlighted

Re: Search head pooling and authorize.conf

Builder

Answering my own question, this situation has been documented.
(5.0.2, 4.3.5)

View solution in original post

0 Karma
Highlighted

Re: Search head pooling and authorize.conf

Builder

Maybe I should've searched better, but hopefully the link to the doc is useful to you. 🙂

0 Karma
Highlighted

Re: Search head pooling and authorize.conf

Splunk Employee
Splunk Employee

That is how we handle authorize.conf. We have the common (shareable) information in a "splunk_system" app and the server specific information in $SPLUNK_HOME/etc/system/local. We do this for all the $SPLUNK_HOME/etc/system/local config files.

0 Karma