Splunk Enterprise Security

Enterprise Security admin privileges, why

tlmayes
Contributor

We have a growing Splunk environment with one ES SH, and a SH cluster. We have an MSS that is going to manage our ES server as part of the managed SOC, we manage/administer everything else internally.

I understand the ES "best practices" dictate that for ES to be properly managed admin access is required. The problem is that this gives the managed SOC complete access to 100% of our data, including indexes that have nothing to do with ES.

What have others done to overcome this requirement of admin access, yet still allow ES and those that manage ES to work properly?? Or is there no alternative that works?

0 Karma

tlmayes
Contributor

Thanks for the response Starcher.

I have no ES background, but am responsible for the core architecture. ES was deployed by Splunk PS and is managed by an MSS. I asked this questions several times of PS, and the answer was always the same: ADMIN is required for the MSS, which contradicts the documentation.

The documentation as you point out does indicate that ADMIN is not required. I am more interested in what others are doing in practice (what works). What you you? Do you use the roles effectively as the document indicates? Without having to provide other than a core administrative function of the Splunk ES (same as you would on any Splunk SH?)?

0 Karma

starcher
SplunkTrust
SplunkTrust

Actually best practices are to setup roles. This is in the docs.
http://docs.splunk.com/Documentation/ES/5.1.0/Install/ConfigureUsersRoles

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...