Integrate Splunk SOAR

Splunk SOAR (On-premises) is a Security Orchestration, Automation, and Response (SOAR) system (see Splunk SOAR Guided Product Tour). You can protect access to Splunk SOAR by integrating Splunk SOAR with Identity as a Service. Once integrated, users can use single sign-on to log in to their Splunk SOAR account through Identity as a Service.

Note: This integration was tested using Identity as a Service version 5.31 and Splunk SOAR August 2023 version. Other versions of Splunk SOAR may require integration and configuration steps that differ from those documented in this procedure. In the event of other issues, contact  support@entrust.com for assistance.

To integrate Splunk SOAR with Identity as a Service, you must do the following:

Before you begin, open two browser windows. In one window, log in to your Splunk SOAR administrator account. In the other window, log in to your IDaaS administrator account.

Step 1: Copy the SAML configurations from Identity as a Service

Step 2: Download the metadata file from Identity as a Service

Step 3: Encode the IDaaS metadata file to Base64

Step 4: Configure Splunk SOAR for Identity as a Service authentication

Step 5:  Add Splunk SOAR  to Identity as a Service

Step 6: Create a resource rule to protect access to Splunk SOAR

Step 7: Test the integration