Splunk Cloud Platform

how users are deprovisioned from Splunk Cloud

sc_admin11
Engager

Considering our current setup i.e authentication and Authorization integrated with SAML, how do we
1. mark an user inactive

2. what do we do with his/her knowledge objects.

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I just checked a Splunk Cloud stack and the only users with the delete option are local.  The SAML users do not have the Edit action, therefore no delete.

---
If this reply helps you, Karma would be appreciated.

richgalloway
SplunkTrust
SplunkTrust

1. You can't.  Splunk doesn't know if a user is active or not - only that they pass authentication (or not).  A user never signing in is just a user who never signs in rather than an inactive/expired user.  You can, however, file a support request to have the user removed.

2. Assign the user's KOs to another user.  Go to Settings->All configurations and click the "Reassign Knowledge Objects" button.

---
If this reply helps you, Karma would be appreciated.

sc_admin11
Engager

If we delete user without reassign KO to other user. Than what would happen with that KOs.

@richgalloway 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The KOs will remain, but will become "orphans" (owned by nobody).  They can be re-assigned to another user, however.

---
If this reply helps you, Karma would be appreciated.
0 Karma

sc_admin11
Engager

Is there any search query from which we can get the inactive users? @richgalloway @_JP 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

This query will tell you when each user last logged in.  It's up to you to decide which of them is "inactive".

| rest /services/authentication/users splunk_server=local | table title last_successful_login
---
If this reply helps you, Karma would be appreciated.

sc_admin11
Engager

@richgalloway in table i got empty column for 

last_successful_login

 Screenshot 2023-10-26 at 12.11.48 PM.png

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...

Splunk and Fraud

Watch Now!Watch an insightful webinar where we delve into the innovative approaches to solving fraud using the ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...