We are recently migrated to QRadar. So we decide to decommission the splunk. before decommission we need to stop any user login into splunk?
How can i do that for all users. could you please suggest what actions to be taken.
You might simply disable splunk web interface.
This depends on how you have enabled the access to splunk. If it's via SSO or LDAP just disable it under settings --authentication
If it's local users you need to disable those ID's then under settings--users.