Security

What is the best practice for managing your SAML cache?

pkeller
Contributor

etc/system/local/authentication.conf and etc/system/metadata/local.meta both contain many old entries of users that may no longer be using the platform. The files both get updated automatically when a new user logs in.

On a search cluster, is there a recommended solution for removing these entries?

My plan was just to shutdown the cluster members, removing all the cached data and restarting, but is there a less disruptive way?

Thank you.

Tags (1)
1 Solution

anaidu_splunk
Splunk Employee
Splunk Employee

There are a few ways to clean up the cache;

i) Restart of splunk,
ii) Or run comand below;
./splunk _internal call /authentication/providers/services/_reload -auth admin:changeme

iii) Or hit the rest endpoint;
"| rest splunk_server=* /services/authentication/providers/services/_reload "

View solution in original post

0 Karma

anaidu_splunk
Splunk Employee
Splunk Employee

There are a few ways to clean up the cache;

i) Restart of splunk,
ii) Or run comand below;
./splunk _internal call /authentication/providers/services/_reload -auth admin:changeme

iii) Or hit the rest endpoint;
"| rest splunk_server=* /services/authentication/providers/services/_reload "

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...