Deployment Architecture

SAML SSO on search head cluster behind load balancer

sivagct
Explorer

I have been trying to configure SAML SSO for the search head clusters running behind the LB. Our setup is Splunk WIP (wide IP Port 80) --> two VIPs in each DC which has Splunk search head servers under then listening on port 8000.It is working fine with LDAP settings.

  • We are able to get SSO working by generating the metadata from the individual search head server listening on port 8000. However Load Balancing is not working since it always redirects to the same server where we generated the metadata. How we have generate a saml metadata file such that SAML SSO works with Wide IP? like how it is working with LDAP.
  • I tried changing the saml/acs URL to the WIP but it doesn't work.

Does anyone come across this situation? any ideas how to deal with this>

Thanks in Advance,

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...