<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Regarding the API key for configuring the authentication extension for the OKTA in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Regarding-the-API-key-for-configuring-the-authentication/m-p/685382#M19228</link>
    <description>&lt;P&gt;Hello, We are trying to configure the&amp;nbsp;&lt;SPAN class=""&gt;authentication extensions for the Okta identity provider and below are the steps as per the Splunk documentation.&lt;/SPAN&gt;&lt;SPAN&gt;Log into Splunk Platform as an administrator level user.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;From the system bar, click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Settings &amp;gt; Authentication Methods&lt;/STRONG&gt;.&lt;/DIV&gt;&lt;DIV class=""&gt;Click "Configure Splunk to use SAML". The "SAML configuration" dialog box appears.&lt;/DIV&gt;&lt;DIV class=""&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Script path&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;field within the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Authentication Extensions&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;section of the "SAML configuration" dialog box , type in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;SAML_script_okta.py.&lt;/DIV&gt;&lt;DIV class=""&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Script timeout&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;field, type in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;300s.&lt;/DIV&gt;&lt;DIV class=""&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Get User Info time-to-live&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;field, type in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;3600s.&lt;/DIV&gt;&lt;DIV class=""&gt;Click the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Script functions&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;field.&lt;/DIV&gt;&lt;DIV class=""&gt;In the pop-up window that appears, click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;getUserInfo.&lt;/DIV&gt;&lt;DIV class=""&gt;Under&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Script Secure Arguments&lt;/STRONG&gt;, click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Add Input&lt;/STRONG&gt;.&lt;/DIV&gt;&lt;DIV class=""&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Key&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;field, type in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;apiKey.&lt;/DIV&gt;&lt;DIV class=""&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Value&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;field, type in the API key for your IdP.&lt;/DIV&gt;&lt;DIV class=""&gt;Click "Add input" again.&lt;/DIV&gt;&lt;DIV class=""&gt;In the "Key" field, type in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;baseUrl.&lt;/DIV&gt;&lt;DIV class=""&gt;in the "Value" field, type in the URL of your Okta instance.&lt;/DIV&gt;&lt;DIV class=""&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Save&lt;/STRONG&gt;. Splunk Cloud Platform saves the Okta configuration and returns you to the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;SAML Groups&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;page.&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Could anyone confirm whether these steps will work for the Splunk OnPrem too? or it is applicable for the Splunk Cloud?&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Also, as per Step (In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Value&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;field, type in the API key for your IdP.), we have to provide the API key for the Idp, our security team is asking what permission does the Okta API token needs? any thoughts? Please advice.&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Thank you!&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 25 Apr 2024 02:33:46 GMT</pubDate>
    <dc:creator>dhana22</dc:creator>
    <dc:date>2024-04-25T02:33:46Z</dc:date>
    <item>
      <title>Regarding the API key for configuring the authentication extension for the OKTA</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Regarding-the-API-key-for-configuring-the-authentication/m-p/685382#M19228</link>
      <description>&lt;P&gt;Hello, We are trying to configure the&amp;nbsp;&lt;SPAN class=""&gt;authentication extensions for the Okta identity provider and below are the steps as per the Splunk documentation.&lt;/SPAN&gt;&lt;SPAN&gt;Log into Splunk Platform as an administrator level user.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;From the system bar, click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Settings &amp;gt; Authentication Methods&lt;/STRONG&gt;.&lt;/DIV&gt;&lt;DIV class=""&gt;Click "Configure Splunk to use SAML". The "SAML configuration" dialog box appears.&lt;/DIV&gt;&lt;DIV class=""&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Script path&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;field within the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Authentication Extensions&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;section of the "SAML configuration" dialog box , type in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;SAML_script_okta.py.&lt;/DIV&gt;&lt;DIV class=""&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Script timeout&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;field, type in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;300s.&lt;/DIV&gt;&lt;DIV class=""&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Get User Info time-to-live&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;field, type in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;3600s.&lt;/DIV&gt;&lt;DIV class=""&gt;Click the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Script functions&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;field.&lt;/DIV&gt;&lt;DIV class=""&gt;In the pop-up window that appears, click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;getUserInfo.&lt;/DIV&gt;&lt;DIV class=""&gt;Under&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Script Secure Arguments&lt;/STRONG&gt;, click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Add Input&lt;/STRONG&gt;.&lt;/DIV&gt;&lt;DIV class=""&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Key&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;field, type in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;apiKey.&lt;/DIV&gt;&lt;DIV class=""&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Value&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;field, type in the API key for your IdP.&lt;/DIV&gt;&lt;DIV class=""&gt;Click "Add input" again.&lt;/DIV&gt;&lt;DIV class=""&gt;In the "Key" field, type in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;baseUrl.&lt;/DIV&gt;&lt;DIV class=""&gt;in the "Value" field, type in the URL of your Okta instance.&lt;/DIV&gt;&lt;DIV class=""&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Save&lt;/STRONG&gt;. Splunk Cloud Platform saves the Okta configuration and returns you to the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;SAML Groups&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;page.&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Could anyone confirm whether these steps will work for the Splunk OnPrem too? or it is applicable for the Splunk Cloud?&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Also, as per Step (In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Value&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;field, type in the API key for your IdP.), we have to provide the API key for the Idp, our security team is asking what permission does the Okta API token needs? any thoughts? Please advice.&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Thank you!&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 25 Apr 2024 02:33:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Regarding-the-API-key-for-configuring-the-authentication/m-p/685382#M19228</guid>
      <dc:creator>dhana22</dc:creator>
      <dc:date>2024-04-25T02:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: Regarding the API key for configuring the authentication extension for the OKTA</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Regarding-the-API-key-for-configuring-the-authentication/m-p/687362#M19385</link>
      <description>&lt;P&gt;You've shared the splunk enterprise manual to set up scripted authentication extensions with okta with us.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.1/Security/ConfigureauthextensionsforSAMLtokens#Configure_and_activate_authentication_extensions_to_interface_with_Okta" target="_blank"&gt;Configure authentication extensions to interface with your SAML identity provider - Splunk Documentation&lt;/A&gt;&lt;/P&gt;&lt;P&gt;So that should be fine if you proceed with this manual.&lt;/P&gt;&lt;P&gt;Regarding the permissiona check the python script and the endpoints that are used in the script. Probably based on the endpoints you could figure out with your IAM colleagues which capabilities are needed.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 16:41:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Regarding-the-API-key-for-configuring-the-authentication/m-p/687362#M19385</guid>
      <dc:creator>PaulPanther</dc:creator>
      <dc:date>2024-05-13T16:41:44Z</dc:date>
    </item>
  </channel>
</rss>

