Turn on Cisco Identity for your Splunk Cloud Platform deployment

Turn on Cisco Identity (CUI) in Splunk Web to give your Splunk Cloud Platform users access to Cisco Cloud Control features.

Before you turn on CUI, confirm that your deployment meets the following requirements:

  • Your Splunk Cloud Platform deployment runs version 10.6 or higher.
  • Your Splunk user account has the sc_admin role.
  • You have administrator access to your organization's identity provider (IdP).
  • If your deployment includes non-default search heads, your IdP's service provider URL uses dot notation for those search heads (sh.stack-name.splunkcloud.com), not dash notation (sh-stack-name.splunkcloud.com). See Cisco Identity and Cisco Cloud Control for details on this requirement.

Turn on Cisco Identity (CUI) to give your Splunk Cloud Platform users access to Cisco Cloud Control features such as AI Canvas, a natural language interface for data analysis. After you turn on CUI, Splunk Cloud Platform requires that users verify their email address when they log in.

The CUI option appears on the Authentication Methods page in Splunk Web for administrators with the sc_admin role on eligible deployments where CUI resources are provisioned. CUI resources are automatically provisioned for eligible AWS commercial deployments when they upgrade to version 10.6. CUI is not available for all Splunk Cloud Platform deployments.

  1. Log in to Splunk Web as a user with the sc_admin role.
  2. From the system bar, select the gear icon > Authentication Methods.
  3. Find the Cisco Identity section and review the current state of the CUI option.

    If the CUI option isn't visible, your deployment doesn't yet have CUI resources provisioned. Contact Splunk Support for assistance.

  4. If your deployment includes non-default search heads, confirm that your IdP uses dot notation URLs for those search heads before you continue.
    CAUTION: Turning on CUI before your IdP uses dot notation for non-default search heads prevents users from logging in to those search heads. If this happens, see the recovery steps in the following section.
  5. Select "Enable Cisco Identity and email verification" to turn on the CUI option.

    After you turn on the CUI option, Splunk Cloud Platform requires that users verify their email address when they log in. Each user must complete the email verification step on their next login. After a user verifies their email address, their Cisco Cloud Control account is created and they can access Cisco Cloud Control features.

CUI is turned on for your Splunk Cloud Platform deployment. Users can access Cisco Cloud Control features after they verify their email address.

Note: Users can skip email verification and continue to access the Splunk platform normally, but they can't access Cisco Cloud Control features until they complete verification.

If users can't log in after you turn on CUI, restore access by going to your Splunk Web login page and adding the following parameters to the URL:

CODE
https://your-deployment.splunkcloud.com/en-US/account/login?skip_sis=true

This URL bypasses CUI and lets administrators log in using their configured authentication method. Use this login to turn off CUI and investigate the problem.