Security

Why does enabling Duo in Splunk break local admin login and is there a way around that?

wrangler2x
Motivator

I'm on the 6.5.2 release and I have Duo turned on in the Splunk configs. It has been working great, but I just found out that I cannot login as user admin in Splunk Web. I get this message:

Access Denied. The username you have entered cannot authenticate with Duo Security. Please contact your system administrator.

That's rather inconvenient! Surely there is a way around this?

mstjohn_splunk
Splunk Employee
Splunk Employee

hi @wrangler2x,

are you using the Duo Splunk Connector or the Duo Log Add-on?

0 Karma

wrangler2x
Motivator

No, this has nothing to do with add-on software. I've configured Splunk to require Duo MFA at logon time. See this here:

https://docs.splunk.com/Documentation/Splunk/7.1.2/Security/ConfigureDuo

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...