Security

Native Password Complexity in Splunk

pj
Contributor

Is there anyway to enforce password complexity using Splunk's native user/password authentication?

Specifically I am looking for:

  1. First time user logs in, they must change their password in Splunk's user screen
  2. Password must follow a minimum defined complexity (e.g. uppercase, lowercase, numbers, special chars and a certain length)
  3. After x months, user must change their password again

I realise that it can be done through SSO, LDAP integration etc. but I am looking for something within Splunk itself (or perhaps some kind of script) as none of these other mechanisms are an option for us right now.

Tags (1)
1 Solution

araitz
Splunk Employee
Splunk Employee

At this time, we don't have plans to implement this kind of improvement in the native Splunk authentication mechanism. The best practice is to use LDAP authentication with Splunk.

I know you mentioned that LDAP is not an option, but it isn't that hard to set up and maintain OpenLDAP.

View solution in original post

israelgutierrez
Path Finder

Hi, i saw this is an old post but the question is the same, now in the new versions of Splunk is there an way to do this? or is in the path to do it?

0 Karma

araitz
Splunk Employee
Splunk Employee

At this time, we don't have plans to implement this kind of improvement in the native Splunk authentication mechanism. The best practice is to use LDAP authentication with Splunk.

I know you mentioned that LDAP is not an option, but it isn't that hard to set up and maintain OpenLDAP.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...