Security

What's the quickest way to lock a user out of Splunk?

the_wolverine
Champion

We've discovered a malicious user (hypothetical) using our Splunk instance. What's the quickest way to lock out this user?

1 Solution

the_wolverine
Champion

If its a local user, change the user's password.

If its an ldap user, create a local account for that user which will override the ldap account.

View solution in original post

the_wolverine
Champion

If its a local user, change the user's password.

If its an ldap user, create a local account for that user which will override the ldap account.

Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...