<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Missing Logout option - Enterprise license, LDAP Authentication in Security</title>
    <link>https://community.splunk.com/t5/Security/Missing-Logout-option-Enterprise-license-LDAP-Authentication/m-p/526660#M11924</link>
    <description>&lt;P&gt;Currently using LDAP authentication, enterprise license for splunk version 7.3.3&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know there was a similar issue in previous versions when SSO was used, and again if you were on a free license.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;to meet&amp;nbsp;CCI-002364, a logout message needs to be recorded. but there is no logout option.&amp;nbsp; Could this be do to CAC authentication?&amp;nbsp; Does anyone know if there's a workaround? Or why the logout option does not exist for users?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Oct 2020 15:06:37 GMT</pubDate>
    <dc:creator>ndoerfler</dc:creator>
    <dc:date>2020-10-27T15:06:37Z</dc:date>
    <item>
      <title>Missing Logout option - Enterprise license, LDAP Authentication</title>
      <link>https://community.splunk.com/t5/Security/Missing-Logout-option-Enterprise-license-LDAP-Authentication/m-p/526660#M11924</link>
      <description>&lt;P&gt;Currently using LDAP authentication, enterprise license for splunk version 7.3.3&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know there was a similar issue in previous versions when SSO was used, and again if you were on a free license.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;to meet&amp;nbsp;CCI-002364, a logout message needs to be recorded. but there is no logout option.&amp;nbsp; Could this be do to CAC authentication?&amp;nbsp; Does anyone know if there's a workaround? Or why the logout option does not exist for users?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2020 15:06:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Missing-Logout-option-Enterprise-license-LDAP-Authentication/m-p/526660#M11924</guid>
      <dc:creator>ndoerfler</dc:creator>
      <dc:date>2020-10-27T15:06:37Z</dc:date>
    </item>
    <item>
      <title>Re: Missing Logout option - Enterprise license, LDAP Authentication</title>
      <link>https://community.splunk.com/t5/Security/Missing-Logout-option-Enterprise-license-LDAP-Authentication/m-p/526722#M11925</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/153720"&gt;@ndoerfler&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;As mentioned in this question&amp;nbsp;&lt;A title="Logging Out of Splunk" href="https://community.splunk.com/t5/Security/Logging-Out-of-Splunk/m-p/498576#M11560" target="_blank" rel="noopener"&gt;Logging Out of Splunk&lt;/A&gt;, you could change the URL to logout as workaround:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;SPLUNK_HOSTNAME&amp;gt;/en-US/account/logout&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tested with SAML/SSO and It seems to work.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2020 21:03:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Missing-Logout-option-Enterprise-license-LDAP-Authentication/m-p/526722#M11925</guid>
      <dc:creator>alonsocaio</dc:creator>
      <dc:date>2020-10-27T21:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: Missing Logout option - Enterprise license, LDAP Authentication</title>
      <link>https://community.splunk.com/t5/Security/Missing-Logout-option-Enterprise-license-LDAP-Authentication/m-p/526876#M11927</link>
      <description>&lt;P&gt;That would work for myself, and I could do that. But unfortunately not all users or customers that access will be as willing and end up closing the window itself which doesn't give me the logout notification.&amp;nbsp; What we really need is that logout option to show. Or a technical reason as to why it doesn't show.&amp;nbsp; If an auditor were to ask about the CCI, we currently don't have an answer for it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 14:32:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Missing-Logout-option-Enterprise-license-LDAP-Authentication/m-p/526876#M11927</guid>
      <dc:creator>ndoerfler</dc:creator>
      <dc:date>2020-10-28T14:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: Missing Logout option - Enterprise license, LDAP Authentication</title>
      <link>https://community.splunk.com/t5/Security/Missing-Logout-option-Enterprise-license-LDAP-Authentication/m-p/526884#M11928</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Unfortunately splunk didn't record logout or time-out to logs unless you don't do explicit logout from gui.&lt;/P&gt;&lt;P&gt;Here is more about this on previous answer:&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Archive/How-to-calculate-Splunk-session-for-a-user/m-p/482711" target="_blank"&gt;https://community.splunk.com/t5/Archive/How-to-calculate-Splunk-session-for-a-user/m-p/482711&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You could try to ask that they add this somehow to audit events in &lt;A href="https://ideas.splunk.com," target="_blank"&gt;https://ideas.splunk.com,&lt;/A&gt;&amp;nbsp;but as it's quite hard to define "logout/timeout" with exact time, this could be hard to get there.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 14:54:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Missing-Logout-option-Enterprise-license-LDAP-Authentication/m-p/526884#M11928</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-10-28T14:54:15Z</dc:date>
    </item>
  </channel>
</rss>

