Security

Does CLI authentication per LDAP work while web authentication per SAML is activated?

DennisFFM
Explorer

We switched our Splunk web authentication from LDAP to SAML.

Now when I for example try to "apply cluster-bundle", I can't authenticate myself with my LDAP credentials anymore,
only with the local Splunk admin.

Is there a way to configure the CLI authentication to use LDAP while the web authentication works with SAML?

0 Karma
1 Solution

mtulett_splunk
Splunk Employee
Splunk Employee

No unfortunately, as the authentication system is the same for both internally.

I would recommend creating a local admin user for each administrator, using something like DennisFFM_admin, vs your normal DennisFFM account. This way you can have local authentication on the cluster with auditing tied to the user, but still log into the web interface with SSO.

View solution in original post

0 Karma

mtulett_splunk
Splunk Employee
Splunk Employee

No unfortunately, as the authentication system is the same for both internally.

I would recommend creating a local admin user for each administrator, using something like DennisFFM_admin, vs your normal DennisFFM account. This way you can have local authentication on the cluster with auditing tied to the user, but still log into the web interface with SSO.

0 Karma

DennisFFM
Explorer

Hi @mtulett, thank you for your answer.

I think that's actually the best way to do it.
I hope there will be a possibility in the future to configure a different authentication system for CLI users.

Cheers!

Dennis

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...