All Apps and Add-ons

How to run a Splunk search using PowerShell against Splunk Cloud that has been federated

nentwich
New Member

My company's Splunk instance is located on Splunk Cloud and authentication to Splunk Cloud is via an ADFS federation server. I have downloaded the Splunk PowerShell Resource Kit and PowerShell search cmdlets from Splunk. Using the documentation provided I am trying to connect to Splunk Cloud and run a query by running the following command:

$a = get-credential
search-splunk -Credential $a -host company.splunkcloud.com -searchstring 'search stuff'

As I do not have a Splunk Cloud account and when using the Splunk Cloud website I am redirected to my company's ADFS server first for authentication before I can interact with website. So I am not sure how to authenticate to Splunk Cloud so I can use the PowerShell cmdlets?

Any help with this would be most appreciated.

Thanks,
Joel

0 Karma

xavierashe
Contributor

have you tried this?

search-splunk -UseDefaultCredentials -host company.splunkcloud.com -searchstring 'search stuff'
0 Karma

nentwich
New Member

@xavierashe Thank you for the response but the search-splunk cmdlet that I am running does not have a -UseDefaultCredentials switch. I am running version 0.2.0 of the cmdlets. Is there a more updated version of the cmdlets that include this switch?

0 Karma

xavierashe
Contributor

Ah, I assumed that they had just extended Invoke-RestMethod. According to the github, they are no longer maintain the PowerShell Resource Kit. Take a look at this script and change

-Credential $MyCredential

to

-UseDefaultCredentials
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...