Skip to main content
Warning
This app is archived. App archiving documentation
Alert action for SAML user role map removal app icon

Alert action for SAML user role map removal

This is a small utility to allow you to remove the SAML user role map from the Splunk instance as an alert action, usually in response to a log event when that user is removed or deactivated in your organisation. This helps keep the Splunk user list clean and stops any scheduled searches owned by that user from continuing to execute.Built by Luke Monahan
splunk product badge

Default Version 1.0.0

July 30, 2021

Compatibility

Splunk Enterprise

Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0

Rating
0
(0)

Log in to rate this app

Support
Archived Add-on

This is a small utility to allow you to remove the SAML user role map from the Splunk instance as an alert action, usually in response to a log event when that user is removed or deactivated in your organisation. This helps keep the Splunk user list clean and stops any scheduled searches owned by that user from continuing to execute. It ultimately executes DELETE https://splunkhost:8089/services/admin/SAML-user-role-map/user@myorg.com, so use the documentation for that to understand what will happen. The alert action is only visible to admin level users.