Splunk Search

How to setup DOD CAC Login for Splunk Web

scc00
Contributor

I have been asked to ensure that the DOD CAC can be used to log into the Splunk Search Heads. Does anyone know how to do this? Is there any documentation somewhere i can reference.

Thanks much.

Tags (2)
0 Karma

elliotproebstel
Champion

In our environment, users log in to their workstations with a card that is similar to DOD CAC. Their authentication is done with an ADFS server. When they access Splunk, we are using SAML authentication to verify their identity. Is this what you're looking for? If so, there are a few options:

  1. Your users are all in the same "user" role bucket and don't need a lot of specialized roles - in this case, you can use Splunk SAML authentication to pass UPN values.
  2. Your users have different roles, and those roles can be maintained in your ADFS records - in this case, you can still use Splunk SAML authentication, and ADFS will pass UPN and role info.
  3. Your users have different roles, and those roles need to be managed within Splunk, because you can't be bothering the ADFS team to manage those roles - in this case, you can wrap Splunk with Apache, acting as a reverse proxy, and shibboleth, which manages the SAML.
0 Karma

scc00
Contributor

Thanks so much for the response. No i was more looking into how to get them to log into Splunk using the CAC without involving any third party tools. Is that possible?

0 Karma

elliotproebstel
Champion

Do you mean you want them to use a CAC to log in without having some kind of SSO identity provider, such as ADFS? I don't know of any such way to do that. But if Splunk is running in a traditional enterprise environment where users a logging into their workstations with a CAC, then integration with ADFS is pretty straightforward.

0 Karma

scc00
Contributor

As it turns out splunk does not have any direct method. So they provided documentation to utilize a proxy with the CAC.

0 Karma

don1966
Loves-to-Learn Everything

Good morning,

May I have a copy of that documentation? I am trying to get the same thing done with our Splunk server.

 

Thank you

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...