Hi,
I am trying to set up RSA authentication on our search head cluster,
I was doing this via the Web Gui but i seem to have locked myself out,
Any idea where the configuration file is on the backend so that i can remove the settings so that i am able to log back in?
It is not under system/local where i thought it would be - i think it is in a authentication.conf file somewhere,
Any help would greatly be appreciated,
Abid
nevermind i found it
it is under /opt/splunk/etc/apps/search/local/authentication.conf
you can use the command grep -tl "externalTwoFactor" /opt/splunk/etc
This will help locate the location of this particular file
nevermind i found it
it is under /opt/splunk/etc/apps/search/local/authentication.conf
you can use the command grep -tl "externalTwoFactor" /opt/splunk/etc
This will help locate the location of this particular file