Security

Delete old SAML users on SHCluster

francoisternois
Path Finder

Hi there,

I try to delete old SAML users on a SHCluster with Splunk 7.1.4.
I followed instructions here https://answers.splunk.com/answers/525555/how-do-i-remove-old-saml-users.html but I still have these users in the access control > users page.

More surprisingly, if I request
curl -k -u admin:{password} --request GET https://{searchhead}:8089/services/admin/SAML-user-role-map/{user}
I have a positive answer (user found)

But if I request
curl -k -u admin{password} --request DELETE https://{searchhead}:8089/services/admin/SAML-user-role-map/{user}
It says : In handler 'SAML-user-role-map': Does not exist: /nobody/system/authentication/userToRoleMap_SAML/{user}

These users are not in /etc/users folder nor in authentication.conf file
I also tried with authentication/users method.
I tried to complete with debug/refresh and restart the SHCluster without the expected result.

Any idea ?

Regards,
Francois

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

[Puzzles] Solve, Learn, Repeat: Nested loops in Event Conversion

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...