Security

Why does enabling Duo in Splunk break local admin login and is there a way around that?

wrangler2x
Motivator

I'm on the 6.5.2 release and I have Duo turned on in the Splunk configs. It has been working great, but I just found out that I cannot login as user admin in Splunk Web. I get this message:

Access Denied. The username you have entered cannot authenticate with Duo Security. Please contact your system administrator.

That's rather inconvenient! Surely there is a way around this?

mstjohn_splunk
Splunk Employee
Splunk Employee

hi @wrangler2x,

are you using the Duo Splunk Connector or the Duo Log Add-on?

0 Karma

wrangler2x
Motivator

No, this has nothing to do with add-on software. I've configured Splunk to require Duo MFA at logon time. See this here:

https://docs.splunk.com/Documentation/Splunk/7.1.2/Security/ConfigureDuo

0 Karma

javier_oshiro
Explorer

We are currently trying to get around this issue.
Have you managed to exclude the local admin account from the DUO mfa?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...