Splunk User Behavior Analytics

UBA SAML Authentication Failing- How can I revert the authentication by using the CLI?

adol83
Explorer

Hello Team

We have a UBA 3-nodes architecture. Unfortunately, SAML authentication is required.

We added the SAML xml file under "Manage --> Settings" as suggested. The result is that UBA threw us out of the platform with no chance to login anymore either way.

We have tried to login with the standard UBA user as we have always done as per -- https://docs.splunk.com/Documentation/UBA/5.2.0/Admin/UBALogin -- . Again, this page is misleading  and there is no way to login to Splunk UBA anymore.

So we tried to seek on docs.splunk.com for suggestions. Unfortunately, any Splunk documentation suggest to use the GUI to revert -- which is not possible -- and now we are at dead end.

log.log under caspida is not revealing much. 

2023-07-25 18:39:48.596 error: no permissions found for role(s): %s (user=%s), failing login
2023-07-25 18:39:48.596 error: No permissions found for the roles: undefined

The error page --

https://splunkuba.apps.mediaset.it/saml/acs

{"userError":true,"message":"No permissions are granted to this username."}

but roles and users have been mapped properly.

Does anyone know know how to revert the authentication by using the CLI?

Does anyone know how to deploy SAML authentication ?

Thanks.

Labels (1)
0 Karma

mkz
Explorer

Were you able to find a way to resolve this issue? We're seeing the same thing, complete with the same error message in log.log. 

For future users, the way to get around SSO if the setup fails is to append ?loginType=uba to the end of your login (https://example.com/?loginType=uba)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...