This page explains the initial setup steps for provisioning identities to Splunk,
using TrustLogin as the identity source.
Note: For detailed instructions on using Splunk, please refer to the documentation provided by Splunk.
| Item | Details | |
| Pre-check |
|
|
| Setup Flow / Manual |
Note: After connecting TrustLogin and Splunk using the steps on this page, |
|
| Provisioning Target | 〇 | Supports user provisioning |
| 〇 | Supports group provisioning | |
| SAML Authentication Setup Manual |
How to Configure SAML JIT for Splunk
|
|
| Remarks |
|
|
Setup Steps
Splunk-side Configuration
-
After logging in to Splunk, click the account icon in the top right, then click "My Profile".
-
Click "Show User API Access Token".
-
Click the copy icon next to the displayed token to copy it.
Note: This token cannot be displayed again, so be sure to copy it on this screen. -
Click the "Organizations" tab and check the value of "Realm".
This completes the preliminary setup on the Splunk side. Next, configure the TrustLogin side.
TrustLogin-side Configuration
Log in to the TrustLogin Admin Page, and from the "Admin Page > Settings > Optional Features" menu,
click "Settings" to the right of "Identity Provisioning" to open it.
-
Click "Add Service," enter "splu" or similar in the search field, select "Splunk," and click the "Add" button.
-
You will be redirected to the "Identity Provisioning > Splunk" page.
Click the "Edit" button. -
Enter the following values in "Access Settings" and click the "Register" button.
Connection URL Specify the Splunk endpoint.
Example: https://api.<REALM>.observability.splunkcloud.com/v2
(For <REALM>, specify the organization's realm name that you checked in step 4 of Splunk-side Configuration)Access Token The value copied in step 3 of Splunk-side Configuration -
Click the "Connect" button at the top right of the screen.
-
Once the button status updates to "Connected," the initial setup is complete.
About Values Configurable in Attribute Mapping
You can link any attribute on the TrustLogin side with any attribute on the Splunk side.
For configuration instructions, see here
Available Default Functions
-
You can specify the Common Default Functions for Services.
Next step: The manual for User Sync Settings is here