Identity Provisioning Setup for Splunk

This page explains the initial setup steps for provisioning identities to Splunk,
using TrustLogin as the identity source.

Note: For detailed instructions on using Splunk, please refer to the documentation provided by Splunk.

Item Details
Pre-check
  • Login with Splunk Admin privileges is required.
Setup Flow / Manual

Note: After connecting TrustLogin and Splunk using the steps on this page,
 proceed to User Sync Settings.

Provisioning Target Supports user provisioning
Supports group provisioning
SAML Authentication Setup Manual How to Configure SAML JIT for Splunk
  • You can link the identity provisioning configuration created in this procedure to an existing SAML app. For details on SAML app configuration, please see here.
  • To prevent conflicts in user attribute updates caused by using the identity provisioning feature together with SAML JIT, we recommend not configuring the "SAML Attribute Settings" for any duplicate user attributes when creating a SAML app.
    Note: Behavior depends on the specifications of each service, so please check with the respective SP for details.
Remarks
  • None in particular

Setup Steps

Splunk-side Configuration

  1. After logging in to Splunk, click the account icon in the top right, then click "My Profile".

    Splunk_ID_01.png

  2. Click "Show User API Access Token".

    Splunk_ID_02.png

  3. Click the copy icon next to the displayed token to copy it.
    Note: This token cannot be displayed again, so be sure to copy it on this screen.

    Splunk_ID_03.png

  4. Click the "Organizations" tab and check the value of "Realm".

    Splunk_ID_04.png


    This completes the preliminary setup on the Splunk side. Next, configure the TrustLogin side.

TrustLogin-side Configuration

  1. Log in to the TrustLogin Admin Page, and from the "Admin Page > Settings > Optional Features" menu,
    click "Settings" to the right of "Identity Provisioning" to open it.
    IDProvServiceCommon01.png

  2. Click "Add Service," enter "splu" or similar in the search field, select "Splunk," and click the "Add" button.

    Splunk_ID_05.png

  3. You will be redirected to the "Identity Provisioning > Splunk" page.
    Click the "Edit" button.

    Splunk_ID_06.png

  4. Enter the following values in "Access Settings" and click the "Register" button.

    Connection URL Specify the Splunk endpoint.
    Example: https://api.<REALM>.observability.splunkcloud.com/v2
    (For <REALM>, specify the organization's realm name that you checked in step 4 of Splunk-side Configuration)
    Access Token The value copied in step 3 of Splunk-side Configuration

    Splunk_ID_07.png

  5. Click the "Connect" button at the top right of the screen.

    NotConnected_IDProv.png

  6. Once the button status updates to "Connected," the initial setup is complete.

    Connected_IDProv.png

About Values Configurable in Attribute Mapping

You can link any attribute on the TrustLogin side with any attribute on the Splunk side.
For configuration instructions, see here

Available Default Functions

Next step: The manual for User Sync Settings is here

Identity Provisioning Setup for Splunk

This page explains the initial setup steps for provisioning identities to Splunk,
using TrustLogin as the identity source.

Note: For detailed instructions on using Splunk, please refer to the documentation provided by Splunk.

Item Details
Pre-check
  • Login with Splunk Admin privileges is required.
Setup Flow / Manual

Note: After connecting TrustLogin and Splunk using the steps on this page,
 proceed to User Sync Settings.

Provisioning Target Supports user provisioning
Supports group provisioning
SAML Authentication Setup Manual How to Configure SAML JIT for Splunk
  • You can link the identity provisioning configuration created in this procedure to an existing SAML app. For details on SAML app configuration, please see here.
  • To prevent conflicts in user attribute updates caused by using the identity provisioning feature together with SAML JIT, we recommend not configuring the "SAML Attribute Settings" for any duplicate user attributes when creating a SAML app.
    Note: Behavior depends on the specifications of each service, so please check with the respective SP for details.
Remarks
  • None in particular

Setup Steps

Splunk-side Configuration

  1. After logging in to Splunk, click the account icon in the top right, then click "My Profile".

    Splunk_ID_01.png

  2. Click "Show User API Access Token".

    Splunk_ID_02.png

  3. Click the copy icon next to the displayed token to copy it.
    Note: This token cannot be displayed again, so be sure to copy it on this screen.

    Splunk_ID_03.png

  4. Click the "Organizations" tab and check the value of "Realm".

    Splunk_ID_04.png


    This completes the preliminary setup on the Splunk side. Next, configure the TrustLogin side.

TrustLogin-side Configuration

  1. Log in to the TrustLogin Admin Page, and from the "Admin Page > Settings > Optional Features" menu,
    click "Settings" to the right of "Identity Provisioning" to open it.
    IDProvServiceCommon01.png

  2. Click "Add Service," enter "splu" or similar in the search field, select "Splunk," and click the "Add" button.

    Splunk_ID_05.png

  3. You will be redirected to the "Identity Provisioning > Splunk" page.
    Click the "Edit" button.

    Splunk_ID_06.png

  4. Enter the following values in "Access Settings" and click the "Register" button.

    Connection URL Specify the Splunk endpoint.
    Example: https://api.<REALM>.observability.splunkcloud.com/v2
    (For <REALM>, specify the organization's realm name that you checked in step 4 of Splunk-side Configuration)
    Access Token The value copied in step 3 of Splunk-side Configuration

    Splunk_ID_07.png

  5. Click the "Connect" button at the top right of the screen.

    NotConnected_IDProv.png

  6. Once the button status updates to "Connected," the initial setup is complete.

    Connected_IDProv.png

About Values Configurable in Attribute Mapping

You can link any attribute on the TrustLogin side with any attribute on the Splunk side.
For configuration instructions, see here

Available Default Functions

Next step: The manual for User Sync Settings is here