Splunk Enterprise

transition from local splunk authentication to saml authentication

ips_mandar
Builder

Hi, currently I have local splunk accounts for all users. Now I am setting up SAML (okta) authentication for all those user. So how can I transition each user local account to SAML account without losing there knowledge objects created including any private knowledge objects as well.
Consider I have same username in both i.e. in local as well as SAML account.
What process I should follow please help.
Thanks,

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
If the local usernames are identical to the SAML usernames then you only need to map SAML groups to Splunk roles. The private KOs will not need to change.
---
If this reply helps you, Karma would be appreciated.
0 Karma

ips_mandar
Builder

Thanks @richgalloway 
After mapping SAML groups to Splunk roles do I need to delete local authentication for all users? and which will take precedence while loging in? 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Local authentication has priority over external authentication.  That means you'd need to delete the local accounts, but I believe that will also delete the local KOs.  One workaround is to copy the $SPLUNK_HOME/etc/users directory and restore it after deleting the accounts.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...