Security

Where is the file for access control stored in Splunk Cloud?

namrithadeepak
Path Finder

Hi,

Purely for informational purposes, I would like to know where the file for access control is stored in Splunk Cloud.

Is it stored on the forwarder, indexer, or the search head? If I install a new component (Forwarder, indexer or search head), is it my responsibility to copy this file over to the new component?

I also have Splunk installed on my local machine (for personal use), can I view it then?

Thanks in advance!!

0 Karma
1 Solution

lguinn2
Legend

I don't know exactly what you mean by "access control." There are several files that Splunk uses to determine who can login, their passwords and their roles. For your local machine, you will find this in $SPLUNK_HOME/etc/passwd and in authorize.conf. You may also have configuration files that allow users to login to Splunk with LDAP credentials, etc.

/etc/passwd must exist on all Splunk instances. Other configuration files generally exist only where users login. Usually that is the search head.

You cannot access any of the configuration files directly in Splunk Cloud.

View solution in original post

lguinn2
Legend

I don't know exactly what you mean by "access control." There are several files that Splunk uses to determine who can login, their passwords and their roles. For your local machine, you will find this in $SPLUNK_HOME/etc/passwd and in authorize.conf. You may also have configuration files that allow users to login to Splunk with LDAP credentials, etc.

/etc/passwd must exist on all Splunk instances. Other configuration files generally exist only where users login. Usually that is the search head.

You cannot access any of the configuration files directly in Splunk Cloud.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...