Exam SPLK-1003 All QuestionsBrowse all questions from this exam
Question 70

How can native authentication be disabled in Splunk?

    Correct Answer: B

    To disable native authentication in Splunk, you need to create an empty $SPLUNK_HOME/etc/passwd file. This effectively disables Splunk's native authentication mechanism, allowing you to use external authentication providers such as LDAP or SAML for user authentication.

Discussion
roblawOption: B

B. A blank passwd file disables native authentication.

Sandy_1988Option: B

B is the answer. Refer system admin pdf.

loky0Option: B

B. P151 sys admin pdf

newroseOption: B

B. Create an empty $SPLUNK_HOME/etc/passwd file

toney_muOption: B

Option B https://docs.splunk.com/Documentation/Splunk/9.0.3/Security/Usernameprecedence#:~:text=On%20the%20Splunk%20Enterprise%20instance,Restart%20Splunk%20Enterprise.

LewistOption: B

Answer is B

kolaturkaOption: B

reating an empty passwd file can disable native authentication in Splunk. This can be achieved by creating an empty file named passwd in the $SPLUNK_HOME/etc directory. This method is useful if you want to use an external authentication provider such as LDAP or SAML for user authentication. Option D (nativeAuthentication=false in authentication.conf) can also be used to disable native authentication, but it is a more granular option as it only disables certain parts of the native authentication system.