Splunk supports multiple authentication methods. Native authentication stores credentials locally in Splunk's own user database — simple but doesn't scale for large orgs.
LDAP authentication integrates with Active Directory or other LDAP servers, mapping LDAP groups to Splunk roles automatically.
SAML/SSO enables single sign-on through identity providers like Okta, Azure AD, or Ping Identity. Multifactor authentication (MFA) adds an extra layer with Duo or RSA.