Splunk Enterprise Security

Enterprise Security admin privileges, why

tlmayes
Contributor

We have a growing Splunk environment with one ES SH, and a SH cluster. We have an MSS that is going to manage our ES server as part of the managed SOC, we manage/administer everything else internally.

I understand the ES "best practices" dictate that for ES to be properly managed admin access is required. The problem is that this gives the managed SOC complete access to 100% of our data, including indexes that have nothing to do with ES.

What have others done to overcome this requirement of admin access, yet still allow ES and those that manage ES to work properly?? Or is there no alternative that works?

0 Karma

tlmayes
Contributor

Thanks for the response Starcher.

I have no ES background, but am responsible for the core architecture. ES was deployed by Splunk PS and is managed by an MSS. I asked this questions several times of PS, and the answer was always the same: ADMIN is required for the MSS, which contradicts the documentation.

The documentation as you point out does indicate that ADMIN is not required. I am more interested in what others are doing in practice (what works). What you you? Do you use the roles effectively as the document indicates? Without having to provide other than a core administrative function of the Splunk ES (same as you would on any Splunk SH?)?

0 Karma

starcher
Influencer

Actually best practices are to setup roles. This is in the docs.
http://docs.splunk.com/Documentation/ES/5.1.0/Install/ConfigureUsersRoles

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...