Monitoring Splunk

When logging into Splunk via saml we receive "IDP failed to authenticate request. Status Code=""

harrisontravers
New Member

Hi everyone,

When logging into Splunk via saml we receive this code

"IDP failed to authenticate request. Status Code="" Check splunkd.log for more information about the failure."

However, when checking splunkd.log there do not appear to be any entries regarding the authentication failure.

Please advise,

Regards,
Harrison

Labels (2)
0 Karma
1 Solution

woodcock
Esteemed Legend

This is the error that appears when there is a problem authorizing access to Splunk. When you get this error, it means that you have been properly authenticated as you (your credentials were entered correctly), but you are not authorized to access Splunk. This problem is above your pay grade and you need to talk to you SSO admin to get it fixed.

View solution in original post

woodcock
Esteemed Legend

This is the error that appears when there is a problem authorizing access to Splunk. When you get this error, it means that you have been properly authenticated as you (your credentials were entered correctly), but you are not authorized to access Splunk. This problem is above your pay grade and you need to talk to you SSO admin to get it fixed.

Get Updates on the Splunk Community!

User Groups | Upcoming Events!

If by chance you weren't already aware, the Splunk Community is host to numerous User Groups, organized ...

Splunk Lantern | Spotlight on Security: Adoption Motions, War Stories, and More

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...