3

Users, Roles, and Authentication in Splunk

Splunk Enterprise follows the role-based access control (RBAC) approach, which allows users to access Splunk instances but restricts what users see and which actions they can perform. As a Splunk system administrator, it’s important to familiarize yourself with Splunk’s default user roles as well as to learn how to create custom roles to meet your organization’s specific requirements. You may also be tested on your understanding of role inheritance, which allows you to assign multiple roles to a user, and how to manage index access for users. It’s important to show that you can set up authentication in Splunk using methods like LDAP, SAML, and more. These skills are tested in the Splunk Enterprise ...

Get Splunk 9.x Enterprise Certified Admin Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.