Splunk Enterprise helps companies collect, analyze, and act upon the data generated by their technology infrastructure, security systems and business applications. Customers use Splunk software to achieve operational visibility into critical information technology assets and drive operational performance and business results.
Splunk Apps enhance and extend the Splunk platform and deliver a user experience tailored to typical tasks and roles. Most customers make use of one or more of the 1000+ Apps available in Splunkbase.
While end-users are the main consumers of Apps, App installation requires full administrator access. We strongly discourage customers from granting this access to any user other than designated administrators.
Beyond restricting admin privileges, we recommend adopting the standard deployment and operation practices described briefly below and detailed in the Splunk Enterprise documentation and Securing Splunk section.
List Users: $SPLUNK_HOME/bin/splunk list user
List Roles: $SPLUNK_HOME/bin/splunk btool authorize list
Splunk also has an Application Certification Program as part of Splunkbase. Customers can choose to use only apps that have been reviewed for technical settings including security.
If you find or suspect a vulnerability in Splunk Enterprise, we’ll be glad to investigate! Let us know via the Splunk Security Portal or submission form.
----------------------------------------------------
Thanks!
Thomas Chimento
The world’s leading organizations rely on Splunk, a Cisco company, to continuously strengthen digital resilience with our unified security and observability platform, powered by industry-leading AI.
Our customers trust Splunk’s award-winning security and observability solutions to secure and improve the reliability of their complex digital environments, at any scale.