Splunk Cloud Platform

Securing Splunk Cloud Platform

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

About user authentication

Authentication lets you add users, assign them to roles, and give those roles access to resources as you need for your organization. The Splunk platform has several schemes that you can use for authentication. You must have an active license for authentication to work.

The Splunk platform uses the following authentication schemes:

Scheme Splunk platform types Description
Native Splunk authentication all Native Splunk authentication takes precedence over any external authentication schemes. The native scheme provides the Admin, Power, and User roles by default. You can define your own roles using a list of Splunk capabilities. If you have an active license, native authentication is on by default. See Set up native Splunk authentication for more information.
Lightweight Directory Access Protocol (LDAP) all The Splunk platform supports authentication with its internal authentication services or your existing LDAP server. See Set up user authentication with LDAP for more information.
Security Assertion Markup Language (SAML) all The Splunk platform supports contacting an identity provider (IdP) that uses the SAML version 2.0 protocol and retrieving user information that can be mapped to Splunk roles. See Configure single sign-on with SAML for additional information.
Scripted authentication API Splunk Enterprise Use scripted authentication to integrate Splunk authentication with an external authentication system, such as Remote Authentication Dial-in User Service (RADIUS) or Pluggable Authentication Module (PAM). See Set up user authentication with external systems for more information.

You can create and assign users to roles either in Splunk Web, on Splunk Cloud Platform and Splunk Enterprise, or by editing the authorize.conf configuration file on Splunk Enterprise only. For more information about roles and capabilities, read About role-based user access.

Last modified on 16 September, 2021
PREVIOUS
Use access control to secure Splunk data
  NEXT
Manage Splunk Cloud Platform users and roles

This documentation applies to the following versions of Splunk Cloud Platform: 8.1.2103, 8.2.2104, 8.2.2106, 8.2.2105, 8.2.2107 (latest FedRAMP release), 8.2.2109, 8.2.2111


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters