Splunk Enterprise

Copying Splunk native user accounts from a standaslone SH to a search head cluster. How can I achieve this ?

dm1
Contributor

As the title suggests, I am trying to copy Splunk native user accounts from a standaslone SH to a search head cluster and I only need to migrate specific user accounts, for this, I am planning to copy the respective line from the /etc/passwd file of the standlone SH to the SHC.

However, after checking out this doc it appears if I copy the lines to the existing /etc/passwd file on a SHC member, it won't replicate it. I would have to push the file from the deployer. However, I am not exactly sure how should I do it from the deployer ?

Labels (1)
Tags (2)
0 Karma

joemcmahon
Explorer

https://docs.splunk.com/Documentation/Splunk/9.2.1/DistSearch/PropagateSHCconfigurationchanges

Regarding the etc/passwd changes, my guess would be "don't do it".  I think the encryption of the passwords must be redone.  Use the UI for password changes so it replicates across the cluster.

0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...