Accessing splunk enterprise using ADFS authentication ?


Is there anyway we can use ADFS to gain access to SPLUNK on-premise ?

Tags (2)


Ok it took me long than I wished but here is how to get splunk working with Centos 6 and ADFS 2.0 using mellon for the SAML implementation. I think splunk should integrate this into their software so we don't need to use something like apache as a proxy server.

First, make sure you have apache installed and set up.
Second, you'll need to set up LDAP inside of splunk using Access controls because SAML SSO, right now, only passes the username. There isn't any support for groups or email addresses, that I could find. LDAP is necessary for group information so splunk knows who the user is based on their username and because of their group, what permission in splunk they should have.

Install the mellon apache module.

yum install mod_auth_mellon

Set up mellon by creating a folder and running the mellon metadata script to create keys and an xml file

mkdir /etc/httpd/mellon

You'll need the federation metadata xml from adfs, the usual url for ADFS 2.0 is Save this file as /etc/httpd/mellon/idp-metadata.xml

Create your apache vhost, in my vhost, I have set up SSL, you don't need SSL but I recommended it.

Splunk Virtual Host

ServerAlias splunk

Redirect Permanent /

ServerAlias splunk
DocumentRoot /var/www/html
<Directory /var/www/html/>
       Require all granted
SSLEngine on
SSLCertificateFile /etc/httpd/ssl/
SSLCertificateKeyFile /etc/httpd/ssl/
SSLCertificateChainFile /etc/httpd/ssl/

<Proxy *>
    Order deny,allow
    Allow from all
ProxyPass /secret/ !
ProxyVia On

ProxyRequests Off

<IfModule auth_mellon_module>
    <Location />
        # Add information from the auth_mellon session to the request.
        MellonEnable "auth"
        Require valid-user
        AuthType "Mellon"
        MellonVariable "cookie"

        # Configure the SP metadata
        # This should be the files which were created when creating SP metadata.
        MellonSPPrivateKeyFile /etc/httpd/mellon/
        MellonSPCertFile  /etc/httpd/mellon/
        MellonSPMetadataFile /etc/httpd/mellon/
        # IdP metadata. This should be the metadata file you downloaded from the IdP.
        MellonIdPMetadataFile /etc/httpd/mellon/idp-metadata.xml

        # The location all endpoints should be located under.
        # It is the URL to this location that is used as the second parameter to the metadata generation script.
        # This path is relative to the root of the web server.
        MellonEndpointPath /secret/endpoint

        RewriteEngine on
        # These lines are to take in the username as known by mellon and rewrite it into REMOTE_USER
        # ADFS passes the username as DOMAIN/USERNAME, the edit line is pull out just the USERNAME
        # Splunk wants only the USERNAME
        RequestHeader set REMOTE_USER "%{MELLON_NAME_ID}e"
        RequestHeader edit REMOTE_USER "^.*\\\(.*)" "$1"


Take the file /etc/httpd/mellon/ and use it to create an ADFS relaying party trust.
In the properties of this new trust, make sure to set, under the advanced tab, the secure hashing algorithm to SHA-1.

You'll need to set up a claim rule in ADFS. Right click your relaying party trust for splunk, and click edit claim rules.
Add a rule, pick Transform an Incoming Claim, name it anything, for example Transform Windows Name to NameID
Set Incoming type to Windows Account Name
Set Outgoing type to Name ID
Set Outgoing name ID format to Transient Identifier
Click ok

Configure splunk
In the file {SPLUNK_HOME}/etc/system/local/server.conf add:


In the file {SPLUNK_HOME}/etc/system/local/web.conf , if the file doesn't exist, create it, add:

trustedIP =
remoteUser = REMOTE_USER
SSOMode = strict
tools.proxy.on = False
tools.proxy.base = link text

Note: I have SSOMode set to strict. That means people can only log in through SSO, if you change it to permissive, then anyone who goes to will be able to use a local splunk user instead of SSO.
By setting tools.proxy.base to the url of the splunk server, I can turn on tools.proxy.on which lets splunk understand X-Forwarded-For headers.

Restart splunk.
Restart/Graceful apache

Try to go to, if everything worked it should prompt your for ADFS credentials and log you in.
You can try to use to debug what is going on.

Hopefully this will either just work or get you far enough to figure out the rest. Good Luck

EDIT: fixed some formatting issues
EDIT: Updated the web.conf file with something that actually works.

Path Finder

We're working on the same issue. We're using as the SP with Apache infront of Splunk. If you have something working let us know as we're in the middle of it.

We hope to have all this working soon and we'll be glad to share the results.

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!