Security
Highlighted

Search head pooling and local users

Path Finder

I'm testing search head pooling and I noticed, that when I add new user on first search head, second search head does not see that user and it cannot log in. I see directory of that user in the SHARED_PATH/etc/users/, but it is only visible on the user list by that search head, where I have created it. The same happen when I create user on the second search head - the first one does not see that user on the user list.
Is this a bug? Feature? How to fix it?

Tags (3)
0 Karma
Highlighted

Re: Search head pooling and local users

Communicator

I don't think that we should call this a feature 🙂

We have been using search head pooling in the past with local authentication and the issue was the same. We have agreed to define new users only on one of the search heads and replicated the files with the users and roles by cron job once per day:

$SPLUNKHOME/etc /passwd (User, passwords, role assignment)
$SPLUNK
HOME/etc/system/local/authorize.conf (role definition)

But this is just kind of work around. Later on we switched to a scripted authentication system.

View solution in original post

0 Karma
Highlighted

Re: Search head pooling and local users

Path Finder

It´s still happening on 6.1.1 but i could see that everything was being written on the nfs folder, not on the /opt/splunk folder.

Re-starting splunk does not solve it.

App instalation is automatic on the other search head, i mean, the one that was not installing the App.

0 Karma
Highlighted

Re: Search head pooling and local users

Path Finder

If obects like reports/alerts/dashboards are available across all search-heads in a pool, isn't it logical to assume that so would be the users? But they are not! (On 6.2.2)

0 Karma