Splunk Enterprise

Auto Inactivity lockout when using SAML

ar2508
Observer

Hi,

We've setup our Splunk instances to use SAML for signon, but are having difficulty setting a time an automatic inactivity logout.

I've configured it to be 5m in both web.conf and server.conf but still don't get an automatic logout.

It does seem to logout automatically every 24hours (not consistently), but when this happens Splunk redirects to the IDP which then redirects back to Splunk with a new SAML token. This happens without the IDP even asking for login details from the user.

 

Any help would be appreciated 

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...