-
Book Overview & Buying
-
Table Of Contents
-
Feedback & Rating

Advanced Splunk
By :

SAML is an XML standard that allows secure web domains to exchange user authentication and authorization data. It allows one online service provider to contact an identity service provider in order to authenticate users who are trying to access the secure content.
Splunk Enterprise supports the use of SAML authentication and authorization for Single Sign-On (SSO). SSO can be enabled in Splunk with the configuration settings provided by the Identity Provider (IdP).
SSO can be configured by Splunk Web or by modifying authentication.conf
located at $SPLUNK_HOME\etc\system\default
directly. At present, Splunk Enterprise supports the Ping Identity product from PingFederate® for SSO.
To configure SSO with SAML, the following is the requirement list:
change_authentication
Splunk capability. This permission allows us to enable SAML and edit authentication settings on the Splunk search head.SSO must be configured on all the search heads in the Splunk deployment for it to function properly.
We'll now learn how to set up SSO using SAML. Let's get acquainted with the steps of setting up SSO:
role
realName
mail
Let's configure SSO using SAML via Splunk Web. The following are the steps to configure SSO on Splunk Web:
localhost:8000
from the deployment server machine or via IPAaddress:PortNo
from a machine in the same network.If all the settings are correct, the SAML Groups page will be populated with all the users and groups where specific groups and Splunk roles can be assigned.
Change the font size
Change margin width
Change background colour