<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are we unable to retrieve the list of all LDAP users? in Security</title>
    <link>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450958#M10520</link>
    <description>&lt;P&gt;Interested to see what the answer ends up being. I'm having a very similar but larger issue. I tried granting extra permissions and even mapping a new group to a new role and the users seem to be stuck with only their original limited access. One of the users I deleted their profile folder from $SPLUNK_HOME/etc/users and it was re-created the next time they logged in, but they did not appear in the Users list (through UI or |rest search) nor did their role get updated.&lt;/P&gt;

&lt;P&gt;In my case it's on a search head cluster.&lt;/P&gt;</description>
    <pubDate>Tue, 26 Mar 2019 00:38:52 GMT</pubDate>
    <dc:creator>anthonymelita</dc:creator>
    <dc:date>2019-03-26T00:38:52Z</dc:date>
    <item>
      <title>Why are we unable to retrieve the list of all LDAP users?</title>
      <link>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450953#M10515</link>
      <description>&lt;P&gt;I was looking at my list of users and noticed that there are quite a few users missing that should be there. We are using LDAP authentication. I checked both Access Controls &amp;gt;&amp;gt; Users and ran &lt;CODE&gt;rest /services/authentication/users splunk_server=local&lt;/CODE&gt;, I got the same partial list each time.&lt;/P&gt;
&lt;P&gt;Currently I'm running 7.1.3, but I had the same problem on older versions as well.&lt;/P&gt;
&lt;P&gt;I saw a few posts referencing that the user may need to log in first before they appear in the list; I can confirm that some users that have recently logged into Splunk are not visible. One of the accounts is my test account that I use frequently in Splunk.&lt;/P&gt;
&lt;P&gt;I turned on debug logging for AuthenticationManagerLDAP and I see entries like this for every user that has Splunk access, including my test account and others that do not appear in the users list:&lt;/P&gt;
&lt;P&gt;DEBUG AuthenticationManagerLDAP - Listing cached user="username"&lt;/P&gt;
&lt;P&gt;I don't see any other errors that might indicate an issue - has anyone run into this problem before?&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 20:02:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450953#M10515</guid>
      <dc:creator>jpetrakovic</dc:creator>
      <dc:date>2020-06-07T20:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we unable to retrieve the list of all LDAP users?</title>
      <link>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450954#M10516</link>
      <description>&lt;P&gt;Have you mapped those missing users into LDAP group in LDAP and mapped that LDAP group with role(s) in Splunk ?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 14:39:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450954#M10516</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2019-03-20T14:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we unable to retrieve the list of all LDAP users?</title>
      <link>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450955#M10517</link>
      <description>&lt;P&gt;Yes, I have. The users can sign into Splunk using their AD credentials and have the permissions granted by their assigned roles. I can even see the users' DNs when looking at the groups in "Map Roles."&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 18:16:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450955#M10517</guid>
      <dc:creator>jpetrakovic</dc:creator>
      <dc:date>2019-03-20T18:16:51Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we unable to retrieve the list of all LDAP users?</title>
      <link>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450956#M10518</link>
      <description>&lt;P&gt;how many splunk instances are connected to LDAP? &lt;/P&gt;</description>
      <pubDate>Sun, 24 Mar 2019 01:24:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450956#M10518</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2019-03-24T01:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we unable to retrieve the list of all LDAP users?</title>
      <link>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450957#M10519</link>
      <description>&lt;P&gt;3 - our indexer, search head, and deployment server. I should have added this in the original description, we have a distributed, non-clustered environment if that makes a difference. I only see this issue on the search head, which is where 95% of my users are logging onto, so it has a lot more role mappings via LDAP than the other instances.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 12:38:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450957#M10519</guid>
      <dc:creator>jpetrakovic</dc:creator>
      <dc:date>2019-03-25T12:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we unable to retrieve the list of all LDAP users?</title>
      <link>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450958#M10520</link>
      <description>&lt;P&gt;Interested to see what the answer ends up being. I'm having a very similar but larger issue. I tried granting extra permissions and even mapping a new group to a new role and the users seem to be stuck with only their original limited access. One of the users I deleted their profile folder from $SPLUNK_HOME/etc/users and it was re-created the next time they logged in, but they did not appear in the Users list (through UI or |rest search) nor did their role get updated.&lt;/P&gt;

&lt;P&gt;In my case it's on a search head cluster.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:38:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450958#M10520</guid>
      <dc:creator>anthonymelita</dc:creator>
      <dc:date>2019-03-26T00:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we unable to retrieve the list of all LDAP users?</title>
      <link>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450959#M10521</link>
      <description>&lt;P&gt;There are two limits that you could hit here, one being Splunk with the default limit in &lt;CODE&gt;authentication.conf&lt;/CODE&gt; being set to 1000:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sizelimit = &amp;lt;integer&amp;gt;
* OPTIONAL
* Limits the amount of entries we request in LDAP search
* IMPORTANT: The max entries returned is still subject to the maximum
  imposed by your LDAP server
  * Example: If you set this to 5000 and the server limits it to 1000,
             you'll still only get 1000 entries back
* Defaults to 1000
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Which is the same as the default size limit in AD &lt;BR /&gt;
&lt;A href="https://support.microsoft.com/en-nz/help/315071/how-to-view-and-set-ldap-policy-in-active-directory-by-using-ntdsutil"&gt;https://support.microsoft.com/en-nz/help/315071/how-to-view-and-set-ldap-policy-in-active-directory-by-using-ntdsutil&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Maybe this helps to find the cause for this.&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:57:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450959#M10521</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2019-03-26T00:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we unable to retrieve the list of all LDAP users?</title>
      <link>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450960#M10522</link>
      <description>&lt;P&gt;I just opened a support ticket. After tweaking some of the LDAP settings, I started to receive size limit errors, so I figured I needed more restrictive query settings. However, after filtering the search down to the point where it should just return 6 users (which it did in a normal ldap search), I still received the size limit errors. I'll let you know what support comes back with! &lt;/P&gt;

&lt;P&gt;For your issue, is your new group in an OU that Splunk is configured to look at? Maybe check your group base DN if you haven't already?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 14:21:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450960#M10522</guid>
      <dc:creator>jpetrakovic</dc:creator>
      <dc:date>2019-03-26T14:21:38Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we unable to retrieve the list of all LDAP users?</title>
      <link>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450961#M10523</link>
      <description>&lt;P&gt;Support was able to figure out this problem, so I figured I would post their fix in case it helps anyone else.&lt;/P&gt;

&lt;P&gt;Apparently this was caused by  functionality difference between an older version of Splunk and Splunk 7.2 (although I had this problem before 7.2).&lt;/P&gt;

&lt;P&gt;In the authorize.conf under my admin role stanza, I had the following two settings:&lt;BR /&gt;
edit_roles_grantable = enabled&lt;BR /&gt;
grantableRoles = system_admin&lt;/P&gt;

&lt;P&gt;These lines used to be required, but now they're not. I removed these lines from authorize.conf, rebooted the search head, and all was well. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:57:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450961#M10523</guid>
      <dc:creator>jpetrakovic</dc:creator>
      <dc:date>2020-09-29T23:57:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we unable to retrieve the list of all LDAP users?</title>
      <link>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450962#M10524</link>
      <description>&lt;P&gt;Perhaps it was the search head reboot that really fixed the issue, though...&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 12:54:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450962#M10524</guid>
      <dc:creator>VexenCrabtree</dc:creator>
      <dc:date>2019-04-05T12:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we unable to retrieve the list of all LDAP users?</title>
      <link>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450963#M10525</link>
      <description>&lt;P&gt;Perhaps it was the search head reboot that really fixed the issue, though...&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 12:55:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450963#M10525</guid>
      <dc:creator>VexenCrabtree</dc:creator>
      <dc:date>2019-04-05T12:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we unable to retrieve the list of all LDAP users?</title>
      <link>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450964#M10526</link>
      <description>&lt;P&gt;Very unlikely as the search head is rebooted regularly for various reasons.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 12:59:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450964#M10526</guid>
      <dc:creator>jpetrakovic</dc:creator>
      <dc:date>2019-04-05T12:59:00Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we unable to retrieve the list of all LDAP users?</title>
      <link>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450965#M10527</link>
      <description>&lt;P&gt;When sizelimit is set to 10000, and we still only can get 1000 rows out of: | rest services/admin/LDAP-groups using SPL, and ldapsearch can easily provide the 10000.&lt;/P&gt;

&lt;P&gt;What is then wrong?&lt;/P&gt;

&lt;P&gt;We running v7.1.3&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2020 09:55:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-are-we-unable-to-retrieve-the-list-of-all-LDAP-users/m-p/450965#M10527</guid>
      <dc:creator>bjarnedein</dc:creator>
      <dc:date>2020-03-23T09:55:58Z</dc:date>
    </item>
  </channel>
</rss>

