Splunk Enterprise

transition from local splunk authentication to saml authentication

ips_mandar
Builder

Hi, currently I have local splunk accounts for all users. Now I am setting up SAML (okta) authentication for all those user. So how can I transition each user local account to SAML account without losing there knowledge objects created including any private knowledge objects as well.
Consider I have same username in both i.e. in local as well as SAML account.
What process I should follow please help.
Thanks,

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
If the local usernames are identical to the SAML usernames then you only need to map SAML groups to Splunk roles. The private KOs will not need to change.
---
If this reply helps you, Karma would be appreciated.
0 Karma

ips_mandar
Builder

Thanks @richgalloway 
After mapping SAML groups to Splunk roles do I need to delete local authentication for all users? and which will take precedence while loging in? 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Local authentication has priority over external authentication.  That means you'd need to delete the local accounts, but I believe that will also delete the local KOs.  One workaround is to copy the $SPLUNK_HOME/etc/users directory and restore it after deleting the accounts.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...