Splunk Enterprise Security

Enterprise Security admin privileges, why

tlmayes
Contributor

We have a growing Splunk environment with one ES SH, and a SH cluster. We have an MSS that is going to manage our ES server as part of the managed SOC, we manage/administer everything else internally.

I understand the ES "best practices" dictate that for ES to be properly managed admin access is required. The problem is that this gives the managed SOC complete access to 100% of our data, including indexes that have nothing to do with ES.

What have others done to overcome this requirement of admin access, yet still allow ES and those that manage ES to work properly?? Or is there no alternative that works?

0 Karma

tlmayes
Contributor

Thanks for the response Starcher.

I have no ES background, but am responsible for the core architecture. ES was deployed by Splunk PS and is managed by an MSS. I asked this questions several times of PS, and the answer was always the same: ADMIN is required for the MSS, which contradicts the documentation.

The documentation as you point out does indicate that ADMIN is not required. I am more interested in what others are doing in practice (what works). What you you? Do you use the roles effectively as the document indicates? Without having to provide other than a core administrative function of the Splunk ES (same as you would on any Splunk SH?)?

0 Karma

starcher
Influencer

Actually best practices are to setup roles. This is in the docs.
http://docs.splunk.com/Documentation/ES/5.1.0/Install/ConfigureUsersRoles

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...