Reporting

After turning on Okta SAML authentication, saved searches and reports are no longer available

ronerf
Explorer

Since i moved authentication from LDAP to SAML, $SPLUNK_HOME/etc/users has a bunch of new username@our.domain directories (the old username directories are still there). What's the best way (migrating the contents of username to username@our.domain? or changing a setting so username settings go back to how they were? something else?) to fix this?

0 Karma

mibrown_splunk
Splunk Employee
Splunk Employee

Your identity provider should be able to map the LDAP usernames to SAML usernames. When you do this, you won't need to reassign knowledge objects including saved searches. In our case we mapped samAccountName to realName (this is a config on the identity provider side) in order to keep user directories the same.

0 Karma

DennisWoerner
Explorer

Hi @ronerf
I've had the same issue as you when I changed the authentication from LDAP to SAML.
My solution was to reassign the Knowledge Objects to the new naming schema because it was only for a couple of users.
I don't know how Okta works but it's generally possible for IDPs to change the way, a username is send to Splunk.

Maybe the Okta Support can help you changing the transfered username or you reassign the Knowledge Objects manually.

Kind regards,
Dennis

Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...