Security

How to write/create permission under /etc from python?

dominiquevocat
SplunkTrust
SplunkTrust

It seems to me that a python script (custom command and/or controller have no write permission under /etc)

Is this me making a mistake or is this a default setting and if so, can it be overcome? (maybe not due to security considerations)

I realize that for a search head cluster this could be non trivial .

0 Karma

micahkemp
Champion

Do you mean the system's /etc, or $SPLUNK_HOME/etc?

If the former, I'd expect that to be the case, unless you have splunk running as root (and I hope you don't). If the latter, I can't see why a custom search command wouldn't have the same permissions to anything under $SPLUNK_HOME, considering it should be running as the same user. I don't believe chroot or anything similar is used when Splunk calls external commands.

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...