Default Version 1.0.0
July 30, 2021
July 30, 2021
Splunk Enterprise
Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0
Log in to rate this app
This is a small utility to allow you to remove the SAML user role map from the Splunk instance as an alert action, usually in response to a log event when that user is removed or deactivated in your organisation. This helps keep the Splunk user list clean and stops any scheduled searches owned by that user from continuing to execute. It ultimately executes DELETE https://splunkhost:8089/services/admin/SAML-user-role-map/user@myorg.com, so use the documentation for that to understand what will happen. The alert action is only visible to admin level users.
Log in to report this app listing.