Splunk Enterprise

Disconnecting from Splunk Web

mello920
Path Finder

Hello,

Does anyone have any idea why this keeps occuring? It happens to me about every 10 minutes. The session timeout is set to 60 minutes. We use SAML with Okta for authentication. I asked the Okta personnel and they said they have a 2 hour time out session. 

Disconnecting from Splunk.png

 

Any help is greatly appreciated!

V/r,

mello920

Labels (2)
0 Karma

ChrisW-TX
Loves-to-Learn Lots

I have a similar issue to this, the exact same behavior as above for a Centrify SAML authenticated Splunk instance, however it happens at 15 minutes on the dot whether you're using the session or not.  Non-SAML Splunk Web sessions don't have this issue.  If you try to do anything in the window as shown above, like refresh, you get an ugly error from the Centrify Connector:

ChrisWTX_0-1663277333391.png

Of course we've engaged Centrify/Delinea but they aren't convinced it's not a problem on Splunk side.  I've verified Splunk is not restarting and there is no timeout or TTL setting I can find that equates to 15 minutes.  Also can't find any events concerning the disconnect in internal Splunk logs or ingested Delinea logs.

Unfortunately this behavior makes our users reluctant to rely on the SAML Sessions.

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@mello920 - I personally have encountered this only when I'm restarting the Splunk service.

Can you please check your Splunk internal logs to see if your Splunk service is getting restarted or not?

index=_* (stop* OR start* OR clos* OR shut OR flush*)

(Please also specify host=<your-SH-host>, to improve the search.)

 

I hope this helps!!!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...