Dashboards & Visualizations

SSO with SAML in distributed environment : Why is data retrieved and seen in inline search, but not when in a dashboard?

gdausque
New Member

Hello,

We are in a distributed configuration. We want to add SSO to Splunk Active Directory Federation Services (ADFS). We have only configured SSO with ADFS on the search head. For the authentication it works fine (with a little bit of works). But we have a strange behavior with dashboard :
- when running the inline search from a panel, no issue : datas are retrieved and displayed correctly
- when running the search from the dashboard : datas are not displayed, we get a no result found

I've tried to add a new panel on an existing dashboard, same issue. On a new dashboard (private or shared), same issue. I think this is related to a role permission, but don't know how to troubleshoot this.

Does anyone had already encountered this behavior, do we need to set up SSO on all node of the Splunk infrastructure (search head and indexer)?

Thanks for your help.

0 Karma

suarezry
Builder

You do not need to setup SSO on the indexer. It's only required for the search head.

If you hover your mouse over the panel a toolbar shows up at the bottom. One of the icons is "open in search", click on this and confirm you do indeed get results. Then click on the "i" icon (inspect). This will open up the Search Job Inspector window. There is a link for "search.log" which you can browse, it will state the reason for why no results are found.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...