Security

Why does enabling Duo in Splunk break local admin login and is there a way around that?

wrangler2x
Motivator

I'm on the 6.5.2 release and I have Duo turned on in the Splunk configs. It has been working great, but I just found out that I cannot login as user admin in Splunk Web. I get this message:

Access Denied. The username you have entered cannot authenticate with Duo Security. Please contact your system administrator.

That's rather inconvenient! Surely there is a way around this?

mstjohn_splunk
Splunk Employee
Splunk Employee

hi @wrangler2x,

are you using the Duo Splunk Connector or the Duo Log Add-on?

0 Karma

wrangler2x
Motivator

No, this has nothing to do with add-on software. I've configured Splunk to require Duo MFA at logon time. See this here:

https://docs.splunk.com/Documentation/Splunk/7.1.2/Security/ConfigureDuo

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...