Security

What is the best practice for managing your SAML cache?

pkeller
Contributor

etc/system/local/authentication.conf and etc/system/metadata/local.meta both contain many old entries of users that may no longer be using the platform. The files both get updated automatically when a new user logs in.

On a search cluster, is there a recommended solution for removing these entries?

My plan was just to shutdown the cluster members, removing all the cached data and restarting, but is there a less disruptive way?

Thank you.

Tags (1)
1 Solution

anaidu_splunk
Splunk Employee
Splunk Employee

There are a few ways to clean up the cache;

i) Restart of splunk,
ii) Or run comand below;
./splunk _internal call /authentication/providers/services/_reload -auth admin:changeme

iii) Or hit the rest endpoint;
"| rest splunk_server=* /services/authentication/providers/services/_reload "

View solution in original post

0 Karma

anaidu_splunk
Splunk Employee
Splunk Employee

There are a few ways to clean up the cache;

i) Restart of splunk,
ii) Or run comand below;
./splunk _internal call /authentication/providers/services/_reload -auth admin:changeme

iii) Or hit the rest endpoint;
"| rest splunk_server=* /services/authentication/providers/services/_reload "

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...