Splunk Enterprise

transition from local splunk authentication to saml authentication

ips_mandar
Builder

Hi, currently I have local splunk accounts for all users. Now I am setting up SAML (okta) authentication for all those user. So how can I transition each user local account to SAML account without losing there knowledge objects created including any private knowledge objects as well.
Consider I have same username in both i.e. in local as well as SAML account.
What process I should follow please help.
Thanks,

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
If the local usernames are identical to the SAML usernames then you only need to map SAML groups to Splunk roles. The private KOs will not need to change.
---
If this reply helps you, Karma would be appreciated.
0 Karma

ips_mandar
Builder

Thanks @richgalloway 
After mapping SAML groups to Splunk roles do I need to delete local authentication for all users? and which will take precedence while loging in? 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Local authentication has priority over external authentication.  That means you'd need to delete the local accounts, but I believe that will also delete the local KOs.  One workaround is to copy the $SPLUNK_HOME/etc/users directory and restore it after deleting the accounts.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...