Security

Splunk CLI permissions and restrictions

jamesoconnell
Path Finder

Hi,

We are administering Splunk for a number of groups. One of these groups is more splunk-sophisticated and has users that are interested in using CLI commands to work directly with their splunk artifacts -- in addition to using the Web UI.

The question is how do we restrict them to using CLI just on their artifacts and not on other groups indexes, forwarders etc.

Regards,
James O'Connell

Tags (2)
0 Karma

woodcock
Esteemed Legend

As far as permissions via roles, CLI vs GUI makes no difference. Just make sure that you have the proper restrictions setup in the users' roles:

http://docs.splunk.com/Documentation/Splunk/latest/Admin/Aboutusersandroles

0 Karma

ndavis4
Explorer

In Linux it is easy enough to give users access to their own application folders/files, however, When a knowledge object is created in the GUI the ownership of that file is Splunk or Root and that user cannot modify it at the CLI. Am I missing something fundamental here?

0 Karma

woodcock
Esteemed Legend

Does this not make sense to you? That is exactly how I would have designed it: the user that is running the Splunk instance (which is usually either splunk or root) is the one that will own all of the KOs from a host-OS perspective. The GUI will allow any user who is logged in to edit his own stuff from the GUI. You can do the SAME THING with the Splunk CLI but you have to use the splunk CLI command to do it (i.e. $SPLUNK_HOME/bin/splunk add ...). As you have found, you cannot use the host OS CLI to do it by using a regular editor.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In September, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...