Security

How do I reload authentication from CLI?

the_wolverine
Champion

My LDAP groups membership lists change often. I need a way to programmatically tell Splunk to reload authentication. Can this be done?

1 Solution

the_wolverine
Champion

Please refer to this blog post on the command you can run from CLI. You can write a cronjob to run the command on a regular basis to keep your group membership list updated automatically.

Note that this only applies to versions 3.x and 4.0.x. In version 4.1, the manner in which we cache LDAP user/group information becomes more dynamic and so reloading authentication is not necessary.

View solution in original post

the_wolverine
Champion
$ splunk _internal call /authentication/providers/services/_reload -auth admin:changeme

the_wolverine
Champion

Please refer to this blog post on the command you can run from CLI. You can write a cronjob to run the command on a regular basis to keep your group membership list updated automatically.

Note that this only applies to versions 3.x and 4.0.x. In version 4.1, the manner in which we cache LDAP user/group information becomes more dynamic and so reloading authentication is not necessary.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Splunk Observability Metrics Cost Optimization

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...