Security

Does CLI authentication per LDAP work while web authentication per SAML is activated?

DennisFFM
Explorer

We switched our Splunk web authentication from LDAP to SAML.

Now when I for example try to "apply cluster-bundle", I can't authenticate myself with my LDAP credentials anymore,
only with the local Splunk admin.

Is there a way to configure the CLI authentication to use LDAP while the web authentication works with SAML?

0 Karma
1 Solution

mtulett_splunk
Splunk Employee
Splunk Employee

No unfortunately, as the authentication system is the same for both internally.

I would recommend creating a local admin user for each administrator, using something like DennisFFM_admin, vs your normal DennisFFM account. This way you can have local authentication on the cluster with auditing tied to the user, but still log into the web interface with SSO.

View solution in original post

0 Karma

mtulett_splunk
Splunk Employee
Splunk Employee

No unfortunately, as the authentication system is the same for both internally.

I would recommend creating a local admin user for each administrator, using something like DennisFFM_admin, vs your normal DennisFFM account. This way you can have local authentication on the cluster with auditing tied to the user, but still log into the web interface with SSO.

0 Karma

DennisFFM
Explorer

Hi @mtulett, thank you for your answer.

I think that's actually the best way to do it.
I hope there will be a possibility in the future to configure a different authentication system for CLI users.

Cheers!

Dennis

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...