All Apps and Add-ons

radius_auth - RADIUS authentication method still employed even with app disable.

jamesaarondevli
Path Finder

Hi,

after successfully authenticating against RADIUS using http://apps.splunk.com/app/981/ I noticed that even once the app was disabled we could still authenticate with RADIUS users (those created prior to disabling app and after).

It is not until we remove $SPLUNK_HOME/etc/system/local/authentication.conf which defines RADIUS as an authentication method that this behaviour ceases.

Cheers,
James

0 Karma

LukeMurphey
Champion

Unfortunately, Splunk doesn't automatically disable the authentication when the app is disabled. To do so, manually, do the following before disabling the app: open the setup page in the RADIUS authentication app, uncheck the "Enable RADIUS authentication" option and press "save".

Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...