Admin Manual

 


Hardening standards

Hardening standards

Splunk recommends using the following guidelines to harden your Splunk instances. Following these guidelines reduces the Splunk attack surface and mitigates the risk and impact of most vulnerabilities.

Service accounts

Splunk components

Network access

Operating System

Availability and reliability

Physical security

Confidentiality and integrity

Authentication

Authorization

Auditing

Configuration management

Client browser

This documentation applies to the following versions of Splunk: 4.2 , 4.2.1 , 4.2.2 , 4.2.3 , 4.2.4 , 4.2.5 , 4.3 , 4.3.1 , 4.3.2 View the Article History for its revisions.


Comments

Rschutt, you can always configure Splunk to map roles to users by specifying the user as the group. Instructions on how to do this can be found here: http://docs.splunk.com/Documentation/Splunk/latest/Admin/SetupuserauthenticationwithLDAP#Map_users_directly

M@
August 15, 2011

Rschutt, this is akin to saying that AD isn't secure because AD administrators can add administrators to the AD administrators group. if your LDAP isn't secure, then you have larger problems.

Rachel
August 15, 2011

LDAP-implementation is NOT secure as Splunk-roles are assigned to LDAP-groups. So anyone who can assign groups to users can assign anyone to the Splunk-admin-role. An enhancement-request is pending under CASE [62163]. This should enable the Splunk-admin to map LDAP-users to Splunk-roles internally ONLY.

Rschutt
August 15, 2011

You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.

Feedback submitted, thanks!