![]() ![]() The Privileged Access Service tenant certificate contains two certificates in chain. Note: Currently Splunk does not support certificate chaining and the certificate provided to Splunk must be publicly verifiable. ![]() p12 file to the application settings in Admin Portal, and upload the public key certificate in a. If you use your own certificate, upload the signing certificate and its private key in a. You can either download one from Admin Portal or use your organization’s trusted certificate. This permission level lets you enable SAML and edit authentication settings on the Splunk search head.Ī signed certificate in both the Splunk web application and Centrify Admin Portal. Splunk SSO Requirementsīefore you configure the Splunk web application for SSO, you need the following:Ī registered Privileged Access Service account and at least one Centrify Connector installed on a Windows computer (if you use only the Privileged Access Service directory as your identity store, you do not need to install the Centrify Connector).Īn active Splunk Enterprise account with administrator rights for your organization.Ĭentrify or your Active Directory configured to provide the role, realName, and mail attributes for the SSO user.Īn admin role with change authentication capability. ![]() If you are not using this version, your interface may differ from the descriptions in this document. Note: This document is written for Splunk On-Premise 8.x. You can configure Splunk for either or both types of SSO. In the event you fall into an unsupported state, you may find support on Splunk Answers or through the open-source communities found on GitHub for this docker-splunk project or the related splunk-ansible project.Splunk offers both IdP-initiated SAML SSO (for SSO access through the Admin Portal) and SP-initiated SAML SSO (for SSO access directly through the Splunk web application). You are using features not officially supported by Splunk.You are running Splunk Enterprise and/or Splunk Universal Forwarder in a container on a platform not officially supported by Splunk.You do not have an active support contract.In the following conditions, Splunk Support reserves the right to deem your installation unsupported and not provide assistance when issues arise: Open a support case on the support portal.If you are a Splunk Enterprise customer with a valid support entitlement contract and have a Splunk-related question, you can Join us on Slack and post in the #docker channel.For all other configurations, contact Splunk Professional Services. Splunk Support only provides support for the single instance Splunk Validated Architectures (S-Type), Universal Forwarders and Heavy Forwarders. Basic instructions to deploy and run Splunk Enterprise inside containers.Supported platforms for containerized Splunk software environments.Docker does not start if the daemon.json file contains badly-formed JSON. Note: If you already have an existing JSON file, add only "storage-driver": "overlay2" as a key-value pair. Assuming the file was empty, add the following contents:.OverlayFS overlay2 Docker daemon storage driver.It's possible that this Docker image still works, although you may need to manually add the environment variable KUBERNETES_SERVICE_HOST=kubernetes to configure the provisioning hooks properly. Note: If you are using podman, CRI-O, containerd or other container runtimes, please be aware that these are currently outside of our support/testing matrix. splunk/universalforwarder image supports both x86-64 and s390x chipsetsĭocker Enterprise Engine 17.06.2 or higherĭocker Community Engine 17.06.2 or higher.splunk/splunk image supports x86-64 chipsets.Linux-based operating system, such as Debian, CentOS, and so on.The following prerequisites and dependencies must be installed on each node you plan on deploying the container. Failure to do so will render your deployment in an unsupported state. If you intend for this containerized Splunk Enterprise deployment to be supported in your Enterprise Support Agreement, you must verify you meet all of the requirements below. Throughout this document, the term "supported" means you can contact Splunk Support for assistance with issues. However, because not all settings apply to all customers, Splunk will only support the most common subset of all configurations. Splunk Enterprise contains many settings that allow customers to tailor their Splunk environment. ![]()
0 Comments
Leave a Reply. |
Details
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |