Splunk Enterprise

SAML authentication with Azure

franciscof
Explorer

Hi guys,

I´m trying to integrate Splunk with SAML authentication and as you may know I have to download a file from Azure and another from Splunk and upload them in the other platform. The thing is that the file I download from Splunk has the "location" field (which is the hostname IP) separated via "-" and not "." so Azure can´t resolve the hostname. This is the "Location" field: 

franciscof_0-1606763503924.png

Also, when I change this value manually it breaks my distributed search configured on m indexers.

Does anyone know how to replace this value in order for Azure to resolve the hostname and finish this SAML integration?

 

Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...