You need to enable multi-factor authentication (MFA) for your Splunk instance. Where is this usually integrated?
SAML is the standard way to delegate MFA to an enterprise IdP.
Why this answer
MFA is typically integrated through the SAML Identity Provider, or via Duo Security integration if using the specific Splunk plugin.