Installation

Can I Install Splunk Enterprise as a non-root user, run Splunk Enterprise as a non-root user, as well as listen directly on a port below 1024?

wellchai0914
New Member

Can I Install Splunk Enterprise as a non-root user, run Splunk Enterprise as a non-root user, as well as listen directly on a port below 1024?

Tags (1)
0 Karma

wellkitkit
Engager

May I know if I can use the setcap to solve non-root user listening to a port below 1024 as below

setcap cap_net_bind_service=ep /opt/splunk/bin/splunkd

gjanders
SplunkTrust
SplunkTrust

From a Unix OS point of view no, you cannot be non-root and listen to a port below 1024

You can use various tricks such as port re-direction to work around this, but a better question is what problem are you trying to solve?
If you need a UDP or TCP listener on a port below 1024 you might want to have a look at syslogNG, I have a post on it here

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...