Splunk Enterprise

Execute CLI commands without password

nicofantinato
Path Finder

Hello to everyone,

as in the title, we'd need to run scripts for putting Splunk search heads in manual detention (but also running other management CLI commands), and we're looking for a way to do that without writing admin's password in plain text inside the command, or leaving it written in user's history.

Is there any way to do that? The only option I found right now is using -auth parameter, while instead the use of rest endpoint is not very clear and I'm not sure it fulfills my requests.

Any help?

Thanks in advance!

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...