November 2018
Beginner
298 pages
7h 51m
English
Splunk authentication is on by default, and remains on even if you select one of the other authentication methods. This means that even if you have a LDAP or SAML username that can log into Splunk, you can also still log in using admin or any other Splunk-defined username.
You create and configure users within Splunk itself by clicking Settings | Access controls on one of the search heads. Clicking Users and then New User allows you to create a new user and assign one of the defined Splunk roles:
Fig 5.1: Creating a Splunk userOut of the box, Splunk comes with several user roles defined. The most basic role is user; ...
Read now
Unlock full access