Splunk Enterprise

transition from local splunk authentication to saml authentication

ips_mandar
Builder

Hi, currently I have local splunk accounts for all users. Now I am setting up SAML (okta) authentication for all those user. So how can I transition each user local account to SAML account without losing there knowledge objects created including any private knowledge objects as well.
Consider I have same username in both i.e. in local as well as SAML account.
What process I should follow please help.
Thanks,

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
If the local usernames are identical to the SAML usernames then you only need to map SAML groups to Splunk roles. The private KOs will not need to change.
---
If this reply helps you, Karma would be appreciated.
0 Karma

ips_mandar
Builder

Thanks @richgalloway 
After mapping SAML groups to Splunk roles do I need to delete local authentication for all users? and which will take precedence while loging in? 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Local authentication has priority over external authentication.  That means you'd need to delete the local accounts, but I believe that will also delete the local KOs.  One workaround is to copy the $SPLUNK_HOME/etc/users directory and restore it after deleting the accounts.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Exciting News: The AppDynamics Community Joins Splunk!

Hello Splunkers,   I’d like to introduce myself—I’m Ryan, the former AppDynamics Community Manager, and I’m ...

The All New Performance Insights for Splunk

Splunk gives you amazing tools to analyze system data and make business-critical decisions, react to issues, ...

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...