Splunk Enterprise Security

ess_admin role issues

astatrial
Contributor

Hello,
I have a splunk cloud managed deployment which has ES installed on it.

First thing is that my user has only ess_admin role without any other Splunk platform admin role, which according to Splunk docs is necessary for ess_admin role.
(https://docs.splunk.com/Documentation/ES/5.2.2/Install/ConfigureUsersRoles).
Is it really a demand for this role ? I have all the needed ES permissions working just fine at the moment.

Second is that i ran the command | rest /services/authorization/roles and i can see that ess_admin role has access to _internal and _* in the "srchIndexDefault", but for some weird reason i don't really have permissions for those kind of indexes and i can't figure out why.

Thanks for any help!!

0 Karma

teunlaan
Contributor

We are running ES with the ess_admin user only, And it works!.

BUT you need to be sure there are no references to admin in de default.meta.

Some config is "owned by admin" and it will fail is tou don't remove is.
We run this to be sure admin is removed:

find . -type f -name default.meta -exec sed -i 's/owner = admin/#owner = admin/g' {} +

and

find . -name *.meta -type f -print | xargs sed -i '/^access/c\access = read : [ * ], write : [ ess_admin ]'
0 Karma

astatrial
Contributor

I think i figured out why it acts like this.

In the srchIndexesAllowed there is nothing, so although that in the srchIndexesDefault there are all the indexes, it doesn't use them.

On the other hand in the srchIndexesAllowed of the user role, there is * which represent according to authorize.conf all the non-internal indexes. So when there is * in ess_admin role Imported_srchIndexesAllowed, it refers to all the non internal indexes.

Still i don't understand if Splunk platform admin role is necessary for ess_admin role...

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...