Security

How to stop all users login into splunk?

Naveen99
Engager

We are recently migrated to QRadar. So we decide to decommission the splunk. before decommission we need to stop any user login into splunk?

How can i do that for all users. could you please suggest what actions to be taken.

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

You might simply disable splunk web interface.

0 Karma

SinghK
Builder

This depends on how you have enabled the access to splunk. If it's via SSO or LDAP just disable it under settings --authentication 

If it's local users you need to disable those ID's then under settings--users.

 

 

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...