Security

Authentication with Tivoli Access Manager WebSEAL (which uses LDAP 3)?

maverick
Splunk Employee
Splunk Employee

If someone wants to integrate Splunk with Tivoli Access Manager WebSEAL for authentication management, which apparently uses IBM LDAP 3, does anyone know if Splunk can do this?

0 Karma

RubenOlsen
Path Finder

Unfortunately Splunk does not support the iv _ groups HTTP header, only iv _ user - so you still will need to let Splunk use LDAP or some scripted authentication solution.

If only Splunk did support the iv _ group HTTP header, putting Splunk behind WebSeal would really be a non-brainer.

0 Karma

maverick
Splunk Employee
Splunk Employee

Yes, Splunk can do this.

Please Note: You will need to set a non-empty root_endpoint path in splunk (probably in web.conf or server.conf, I think) and set the Splunk app up as a "transparent junction" with the same path/endpoint in TAM (i.e. some TAM-related thing that your administrator will have to do) as a regular junction won't work correctly, I believe.

0 Karma
Get Updates on the Splunk Community!

What’s New in Splunk Enterprise 9.4: Tools for Digital Resilience

PLATFORM TECH TALKS What’s New in Splunk Enterprise 9.4: Tools for Digital Resilience Thursday, February 27, ...

Leverage Cisco Talos Threat Intelligence Across Splunk Security Products

Leverage Cisco Talos Threat Intelligence Across Splunk Security Products Wednesday, February 26, ...

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...