Security

Search head pooling and local users

bckq
Path Finder

I'm testing search head pooling and I noticed, that when I add new user on first search head, second search head does not see that user and it cannot log in. I see directory of that user in the SHARED_PATH/etc/users/, but it is only visible on the user list by that search head, where I have created it. The same happen when I create user on the second search head - the first one does not see that user on the user list.
Is this a bug? Feature? How to fix it?

Tags (3)
0 Karma
1 Solution

norbert_hamel
Communicator

I don't think that we should call this a feature 🙂

We have been using search head pooling in the past with local authentication and the issue was the same. We have agreed to define new users only on one of the search heads and replicated the files with the users and roles by cron job once per day:

$SPLUNK_HOME/etc /passwd (User, passwords, role assignment)
$SPLUNK_HOME/etc/system/local/authorize.conf (role definition)

But this is just kind of work around. Later on we switched to a scripted authentication system.

View solution in original post

0 Karma

norbert_hamel
Communicator

I don't think that we should call this a feature 🙂

We have been using search head pooling in the past with local authentication and the issue was the same. We have agreed to define new users only on one of the search heads and replicated the files with the users and roles by cron job once per day:

$SPLUNK_HOME/etc /passwd (User, passwords, role assignment)
$SPLUNK_HOME/etc/system/local/authorize.conf (role definition)

But this is just kind of work around. Later on we switched to a scripted authentication system.

0 Karma

theunf
Communicator

It´s still happening on 6.1.1 but i could see that everything was being written on the nfs folder, not on the /opt/splunk folder.

Re-starting splunk does not solve it.

App instalation is automatic on the other search head, i mean, the one that was not installing the App.

0 Karma

saikatr
Path Finder

If obects like reports/alerts/dashboards are available across all search-heads in a pool, isn't it logical to assume that so would be the users? But they are not! (On 6.2.2)

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...