Dashboards & Visualizations

Why are we getting SAML authentication error "Unable to parse the payload received as a part if idp metadata file or xml." on our Splunk 6.3.1 search head?

metadata
Engager

We tried to enable SAML authentication for our Splunk 6.3.1 Search Head. For this, we tried to import the IdP metadata XML file, but this fails with the following message:

"Unable to parse the payload received as a part if idp metadata file or xml."

We tried to import the IdP xml file provided at Step 3 "Obtain the IdP meta data" of this blog: http://blogs.splunk.com/2013/03/28/splunkweb-sso-samlv2/ but we do obtain the exact same message:

"Unable to parse the payload received as a part if idp metadata file or xml."

Is there a specific format we need to comply to ?

Any help would be very much appreciated.

Thanks

0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

I have a hunch that you're character encoding is bad. Such as you're copying the IDP metadata file/xml to notepad in windows, and then saving and/or copy and pasting to linux search head. Or visa versa you're copying from linux to windows.

You should try using dosutils if in linux. apt-get dosutils, etc... it gives you commands called dos2unix and unix2dos. SO if you're uploading to linux, try running dos2unix on the IDP xml file first, and then maybe use cat to write the file to your console, then copy and paste into the search head on step 3.

View solution in original post

jkat54
SplunkTrust
SplunkTrust

I have a hunch that you're character encoding is bad. Such as you're copying the IDP metadata file/xml to notepad in windows, and then saving and/or copy and pasting to linux search head. Or visa versa you're copying from linux to windows.

You should try using dosutils if in linux. apt-get dosutils, etc... it gives you commands called dos2unix and unix2dos. SO if you're uploading to linux, try running dos2unix on the IDP xml file first, and then maybe use cat to write the file to your console, then copy and paste into the search head on step 3.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...