Security

Search head pooling and local users

bckq
Path Finder

I'm testing search head pooling and I noticed, that when I add new user on first search head, second search head does not see that user and it cannot log in. I see directory of that user in the SHARED_PATH/etc/users/, but it is only visible on the user list by that search head, where I have created it. The same happen when I create user on the second search head - the first one does not see that user on the user list.
Is this a bug? Feature? How to fix it?

Tags (3)
0 Karma
1 Solution

norbert_hamel
Communicator

I don't think that we should call this a feature 🙂

We have been using search head pooling in the past with local authentication and the issue was the same. We have agreed to define new users only on one of the search heads and replicated the files with the users and roles by cron job once per day:

$SPLUNK_HOME/etc /passwd (User, passwords, role assignment)
$SPLUNK_HOME/etc/system/local/authorize.conf (role definition)

But this is just kind of work around. Later on we switched to a scripted authentication system.

View solution in original post

0 Karma

norbert_hamel
Communicator

I don't think that we should call this a feature 🙂

We have been using search head pooling in the past with local authentication and the issue was the same. We have agreed to define new users only on one of the search heads and replicated the files with the users and roles by cron job once per day:

$SPLUNK_HOME/etc /passwd (User, passwords, role assignment)
$SPLUNK_HOME/etc/system/local/authorize.conf (role definition)

But this is just kind of work around. Later on we switched to a scripted authentication system.

0 Karma

theunf
Communicator

It´s still happening on 6.1.1 but i could see that everything was being written on the nfs folder, not on the /opt/splunk folder.

Re-starting splunk does not solve it.

App instalation is automatic on the other search head, i mean, the one that was not installing the App.

0 Karma

saikatr
Path Finder

If obects like reports/alerts/dashboards are available across all search-heads in a pool, isn't it logical to assume that so would be the users? But they are not! (On 6.2.2)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...