Security

How to stop all users login into splunk?

Naveen99
Engager

We are recently migrated to QRadar. So we decide to decommission the splunk. before decommission we need to stop any user login into splunk?

How can i do that for all users. could you please suggest what actions to be taken.

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

You might simply disable splunk web interface.

0 Karma

SinghK
Builder

This depends on how you have enabled the access to splunk. If it's via SSO or LDAP just disable it under settings --authentication 

If it's local users you need to disable those ID's then under settings--users.

 

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...