Splunk Search

how to centralized the splunk login account?

dikaye
Path Finder

Dear Sir,

We will have two indexer servers for our account login to manage they account founctions, so how to centralized the splunk login account?

Tags (1)
0 Karma

Simon
Contributor

You could deploy your $SPLUNK_HOME/etc/passwd. I've done this over multiple indexers/search heads and even over my forwarders.

Or more easier just scp your passwd file to your boxes.

0 Karma

dikaye
Path Finder

Thanks for your comment, for the options 2, if I use openldap, seems splunk can't centralized manage the users account.

Actually, what I want is that two indexer servers can centralized manage the users account.

Looking forward to your reply, thanks.

0 Karma

southeringtonp
Motivator

More detail on your environment and what you are trying to accomplish would be helpful. However, the following may be helpful:

In general, you may wish to consult Set up user authentication in the Splunk docs.

The options are:

  1. Manually create an account with the same name and password on each indexer.
  2. Use LDAP Authentication with an external account store.
  3. Use a scripted authentication for RADIUS or to allow complete customization.
  4. Use an external authentication source and Splunk's support for single-sign-on.

Options (1) or (2) are usually the easiest to maintain for a small number of indexers. Option (2) is particularly recommended if Active Directory or another LDAP provider is available.

Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...