Security

Can I edit Users in Account controls on Splunk Cloud Free Trial?

hettervik
Builder

Hi,

I've started testing out Splunk Cloud for a customer by setting up a Splunk Cloud Free Trial on my personal Splunk account. I know that I can invite users using the portal on Splunk Customer Community, but can I edit user settings using the Splunk GUI/UI? The documentation clearly says one can do so:

"If you do not log into Splunk Cloud through the Splunk Customer Portal, access the Users page of your Splunk Cloud user interface to manage user accounts. If you have administrator rights, you can create, edit, clone, and delete users."

Though, when I enter Splunk Cloud GUI and go to Access controls I only see Roles, not Users and Authentication method, as is usual in normal Splunk Enterprise. I know that I have admin rights, at least according to the portal on Splunk Customer Community. Also, I know that the documentation says that I should "not log into Splunk Cloud through the Splunk Customer Portal", but if I try to invite a user to my Splunk Cloud that is not a Splunk Customer Community user, that users is "forced" to sign up to (or create a new user on) Splunk Customer Community before continuing. Is the documentation outdated, or am I not allowed to manage users on Splunk Cloud because I use a Free Trial?

Any help will be much appreciated! Thanks.

Tags (2)
0 Karma
1 Solution

ytenenbaum_splu
Splunk Employee
Splunk Employee

Yes this is by design doe the trial version. We use single sign on (SSO) using Ping Identity so removed users from the UI. You have to invite people outside the instance. Once the user gets the email invite they need to open a new browser session otherwise there will be an sso token clash. They will also need to register as community users. This is different in the non trial version where you can manage users normall. If you get this message you know you have the clash:
"Access to the Splunk Cloud instance has been denied because the user's registered email does not match the email address associated with the Splunk Cloud Invitation. Please contact your Splunk Administrator and ask them to resend the invitation to the correct email address."
So either open a new browser session or log out and login back again.

View solution in original post

0 Karma

ytenenbaum_splu
Splunk Employee
Splunk Employee

Yes this is by design doe the trial version. We use single sign on (SSO) using Ping Identity so removed users from the UI. You have to invite people outside the instance. Once the user gets the email invite they need to open a new browser session otherwise there will be an sso token clash. They will also need to register as community users. This is different in the non trial version where you can manage users normall. If you get this message you know you have the clash:
"Access to the Splunk Cloud instance has been denied because the user's registered email does not match the email address associated with the Splunk Cloud Invitation. Please contact your Splunk Administrator and ask them to resend the invitation to the correct email address."
So either open a new browser session or log out and login back again.

0 Karma

hettervik
Builder

Thanks! That explains it. 🙂

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...