<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Some LDAP users are not showing up in Splunk Users screen -- Splunk 4.3.1 build 119532. in Security</title>
    <link>https://community.splunk.com/t5/Security/Some-LDAP-users-are-not-showing-up-in-Splunk-Users-screen-Splunk/m-p/73941#M2458</link>
    <description>&lt;P&gt;I happened to take a look at Manager &amp;gt;&amp;gt; Access Controls &amp;gt;&amp;gt; Users the other day and quite a few users I knew should be there were not. We are using LDAP authentication. I vaguely remembered something about LDAP in the 4.3 notes and went and looked. After mentioning that they fixed a bug concerning Splunk LDAP for this release it says:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;If you are using LDAP version 2,&lt;BR /&gt;
Splunk will populate the LDAP user&lt;BR /&gt;
list with only those users who have&lt;BR /&gt;
already successfully logged in to&lt;BR /&gt;
Splunk, as opposed to the full list of&lt;BR /&gt;
users who have login access.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;We are, in fact, using LDAP 2 (the actual version is 2.4.23)&lt;/P&gt;

&lt;P&gt;So I thought, "maybe that's it". I asked someone who is configured to use Splunk via LDAP that was not on the list in Splunk and asked him to log in to Splunkweb. After he did this I went back to the Users list and, no, he still wasn't there. So I don't think it is this that we are seeing here.&lt;/P&gt;

&lt;P&gt;My questions:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Has anyone else seen this?&lt;/LI&gt;
&lt;LI&gt;Has anyone any idea about anything we could be doing that would cause this?&lt;/LI&gt;
&lt;LI&gt;Does this sound like a Splunk bug?&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Thu, 27 Sep 2012 23:21:13 GMT</pubDate>
    <dc:creator>wrangler2x</dc:creator>
    <dc:date>2012-09-27T23:21:13Z</dc:date>
    <item>
      <title>Some LDAP users are not showing up in Splunk Users screen -- Splunk 4.3.1 build 119532.</title>
      <link>https://community.splunk.com/t5/Security/Some-LDAP-users-are-not-showing-up-in-Splunk-Users-screen-Splunk/m-p/73941#M2458</link>
      <description>&lt;P&gt;I happened to take a look at Manager &amp;gt;&amp;gt; Access Controls &amp;gt;&amp;gt; Users the other day and quite a few users I knew should be there were not. We are using LDAP authentication. I vaguely remembered something about LDAP in the 4.3 notes and went and looked. After mentioning that they fixed a bug concerning Splunk LDAP for this release it says:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;If you are using LDAP version 2,&lt;BR /&gt;
Splunk will populate the LDAP user&lt;BR /&gt;
list with only those users who have&lt;BR /&gt;
already successfully logged in to&lt;BR /&gt;
Splunk, as opposed to the full list of&lt;BR /&gt;
users who have login access.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;We are, in fact, using LDAP 2 (the actual version is 2.4.23)&lt;/P&gt;

&lt;P&gt;So I thought, "maybe that's it". I asked someone who is configured to use Splunk via LDAP that was not on the list in Splunk and asked him to log in to Splunkweb. After he did this I went back to the Users list and, no, he still wasn't there. So I don't think it is this that we are seeing here.&lt;/P&gt;

&lt;P&gt;My questions:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Has anyone else seen this?&lt;/LI&gt;
&lt;LI&gt;Has anyone any idea about anything we could be doing that would cause this?&lt;/LI&gt;
&lt;LI&gt;Does this sound like a Splunk bug?&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Thu, 27 Sep 2012 23:21:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Some-LDAP-users-are-not-showing-up-in-Splunk-Users-screen-Splunk/m-p/73941#M2458</guid>
      <dc:creator>wrangler2x</dc:creator>
      <dc:date>2012-09-27T23:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: Some LDAP users are not showing up in Splunk Users screen -- Splunk 4.3.1 build 119532.</title>
      <link>https://community.splunk.com/t5/Security/Some-LDAP-users-are-not-showing-up-in-Splunk-Users-screen-Splunk/m-p/73942#M2459</link>
      <description>&lt;P&gt;What are your LDAP settings? Mainly, what is your "User base DN" and "Group base DN"?  I tend to create a specific Security Group for Splunk.  I have for example Splunk - Admins, Splunk - Developers - Location 1, Splunk - Developers - Location 2, Splunk - Service Desk, etc.  With that, make sure that a group the user is in is mapped to a specific role.  Is the group showing up in the "Manager » Access controls » Authentication method » Configure Splunk to use LDAP and map groups  » Map groups"?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2012 13:15:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Some-LDAP-users-are-not-showing-up-in-Splunk-Users-screen-Splunk/m-p/73942#M2459</guid>
      <dc:creator>treinke</dc:creator>
      <dc:date>2012-09-28T13:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: Some LDAP users are not showing up in Splunk Users screen -- Splunk 4.3.1 build 119532.</title>
      <link>https://community.splunk.com/t5/Security/Some-LDAP-users-are-not-showing-up-in-Splunk-Users-screen-Splunk/m-p/73943#M2460</link>
      <description>&lt;P&gt;Can you be more specific about what you are looking for in the GUI? There is no area of the page labled 'groups'. I will say that every field is filled in except the two Dynamic group settings (member attribute and group search filter).&lt;/P&gt;

&lt;P&gt;We are using a rolemap defined in authentication.conf that has a 10 roles, and what users associated with these roles can do is defined in authorize.conf.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2012 16:56:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Some-LDAP-users-are-not-showing-up-in-Splunk-Users-screen-Splunk/m-p/73943#M2460</guid>
      <dc:creator>wrangler2x</dc:creator>
      <dc:date>2012-09-28T16:56:26Z</dc:date>
    </item>
  </channel>
</rss>

