Deployment Architecture

how to push user account from master/deployment node to SHC members

dhavamanis
Builder

Need your help!,

Can you please tell us, how to push user account from master/deployment node to SHC members and etc/system/local config. We are pushing apps and users folder from etc/shcluster/ using below, but we could see any option to use etc/passwd file to SHC members. also there is no option to push the standalone search head etc/system/local directory config.

./splunk apply shcluster-bundle --answer-yes -target https://1.13.2.1:8089 -auth admin:changeme

Tags (1)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

If you're using Splunk's built-in authentication then you will have to add every user to each cluster member:

http://docs.splunk.com/Documentation/Splunk/6.2.3/DistSearch/AdduserstotheSHC#Use_Splunk_Enterprise_...

martin_mueller
SplunkTrust
SplunkTrust

Great. If that answers your question then please mark the answer as accepted.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

As the path implies, those settings are local to a system. If you want to push them to the cluster you should package them in an app, or configure the settings on each member.

0 Karma

dhavamanis
Builder

Thank you so much for the details.

0 Karma

dhavamanis
Builder

thanks, We are using external SSO authentication, but user permissions are stored in Splunk. Can you please tell us, how to copy the standalone etc/system/local/ (web.conf, transforms.conf..etc) files to SHC nodes?.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...