<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pulling back data from users login in using SAML. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Pulling-back-data-from-users-login-in-using-SAML/m-p/744835#M241327</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/267795"&gt;@CMAzurdia&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My apologies, I thought you were referring to people logging in to Splunk using SAML.&lt;/P&gt;&lt;P&gt;Ultimately this depends on what the data looks like when you receive it in Splunk? Its worth starting by identifying key fields in your data and then filtering down until you just get the events you are interested in - from here you can work through your usecase/requirements.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
    <pubDate>Wed, 23 Apr 2025 21:25:55 GMT</pubDate>
    <dc:creator>livehybrid</dc:creator>
    <dc:date>2025-04-23T21:25:55Z</dc:date>
    <item>
      <title>Pulling back data from users login in using SAML.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Pulling-back-data-from-users-login-in-using-SAML/m-p/744798#M241317</link>
      <description>&lt;P&gt;Hello Splunk team,&lt;/P&gt;&lt;P&gt;I need a search query that can pull data back of successful and unsuccessful login attempts of users login into a server using SAML. I also need to create a dashboard of the results. Any additional information needed, please let me know.&lt;/P&gt;&lt;P&gt;Do I need to extract a field of all the users using SAML?&lt;/P&gt;&lt;P&gt;v/r&lt;/P&gt;&lt;P&gt;cmazurdia&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2025 15:23:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Pulling-back-data-from-users-login-in-using-SAML/m-p/744798#M241317</guid>
      <dc:creator>CMAzurdia</dc:creator>
      <dc:date>2025-04-23T15:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: Pulling back data from users login in using SAML.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Pulling-back-data-from-users-login-in-using-SAML/m-p/744800#M241318</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/267795"&gt;@CMAzurdia&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Typically success/failed login attempts are recorded by the Identity Provider (IdP) rather than Splunk, however you can see successful logins to Splunk from SAML users with the following query:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal method=POST uri=/saml/acs
| table _time user clientip&lt;/LI-CODE&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2025 15:42:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Pulling-back-data-from-users-login-in-using-SAML/m-p/744800#M241318</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-04-23T15:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: Pulling back data from users login in using SAML.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Pulling-back-data-from-users-login-in-using-SAML/m-p/744801#M241319</link>
      <description>&lt;P&gt;The query did not error, but also 0 events. Any other way? I have created a lookup table.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2025 16:16:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Pulling-back-data-from-users-login-in-using-SAML/m-p/744801#M241319</guid>
      <dc:creator>CMAzurdia</dc:creator>
      <dc:date>2025-04-23T16:16:48Z</dc:date>
    </item>
    <item>
      <title>Re: Pulling back data from users login in using SAML.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Pulling-back-data-from-users-login-in-using-SAML/m-p/744806#M241320</link>
      <description>&lt;P&gt;I have a server pushing audit logs data to a syslog, to login to the server you need SAML. My question is: how do I pull data of successful logins and unsuccessful logins of those SAML users in Splunk?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2025 17:33:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Pulling-back-data-from-users-login-in-using-SAML/m-p/744806#M241320</guid>
      <dc:creator>CMAzurdia</dc:creator>
      <dc:date>2025-04-23T17:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: Pulling back data from users login in using SAML.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Pulling-back-data-from-users-login-in-using-SAML/m-p/744835#M241327</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/267795"&gt;@CMAzurdia&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My apologies, I thought you were referring to people logging in to Splunk using SAML.&lt;/P&gt;&lt;P&gt;Ultimately this depends on what the data looks like when you receive it in Splunk? Its worth starting by identifying key fields in your data and then filtering down until you just get the events you are interested in - from here you can work through your usecase/requirements.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2025 21:25:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Pulling-back-data-from-users-login-in-using-SAML/m-p/744835#M241327</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-04-23T21:25:55Z</dc:date>
    </item>
  </channel>
</rss>

