Security
Highlighted

Why does enabling Duo in Splunk break local admin login and is there a way around that?

Motivator

I'm on the 6.5.2 release and I have Duo turned on in the Splunk configs. It has been working great, but I just found out that I cannot login as user admin in Splunk Web. I get this message:

Access Denied. The username you have entered cannot authenticate with Duo Security. Please contact your system administrator.

That's rather inconvenient! Surely there is a way around this?

Highlighted

Re: Why does enabling Duo in Splunk break local admin login and is there a way around that?

Splunk Employee
Splunk Employee

hi @wrangler2x,

are you using the Duo Splunk Connector or the Duo Log Add-on?

0 Karma
Highlighted

Re: Why does enabling Duo in Splunk break local admin login and is there a way around that?

Motivator

No, this has nothing to do with add-on software. I've configured Splunk to require Duo MFA at logon time. See this here:

https://docs.splunk.com/Documentation/Splunk/7.1.2/Security/ConfigureDuo

0 Karma