<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I convert from basic auth to LDAP without losing any user data? in Security</title>
    <link>https://community.splunk.com/t5/Security/How-do-I-convert-from-basic-auth-to-LDAP-without-losing-any-user/m-p/10394#M45</link>
    <description>&lt;P&gt;The easiest way to identify the local Splunkauth users is to check your $SPLUNK_HOME/etc/passwd file which is in the same format as unix passwd.  &lt;/P&gt;

&lt;P&gt;Figure out which of these users correspond to which LDAP users.&lt;/P&gt;

&lt;P&gt;Then locate your user's savedsearches and swap out the userid field with the corresponding ldap userid.&lt;/P&gt;</description>
    <pubDate>Fri, 09 Apr 2010 12:23:24 GMT</pubDate>
    <dc:creator>the_wolverine</dc:creator>
    <dc:date>2010-04-09T12:23:24Z</dc:date>
    <item>
      <title>How do I convert from basic auth to LDAP without losing any user data?</title>
      <link>https://community.splunk.com/t5/Security/How-do-I-convert-from-basic-auth-to-LDAP-without-losing-any-user/m-p/10392#M43</link>
      <description>&lt;P&gt;I'd like to convert a busy server with a bunch of users from default auth to LDAP. How can I do so without losing any of their saved searches and other data?&lt;/P&gt;</description>
      <pubDate>Sat, 20 Mar 2010 06:38:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-I-convert-from-basic-auth-to-LDAP-without-losing-any-user/m-p/10392#M43</guid>
      <dc:creator>Alan_Bradley</dc:creator>
      <dc:date>2010-03-20T06:38:06Z</dc:date>
    </item>
    <item>
      <title>Re: How do I convert from basic auth to LDAP without losing any user data?</title>
      <link>https://community.splunk.com/t5/Security/How-do-I-convert-from-basic-auth-to-LDAP-without-losing-any-user/m-p/10393#M44</link>
      <description>&lt;P&gt;You will have to first identify the local auth user ids (./splunk list user). You will then need to modify your saved searches.conf and swap the userid= field in each stanza to be the ldap userid. I would recommend migrating auth to LDAP, creating one saved search as an LDAP user so you can verify that you have the format of the LDAP userid, and then making the changes to the existing saved searches. Once you finish modifying the savedsearches.conf you will need to restart Splunk.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Mar 2010 06:38:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-I-convert-from-basic-auth-to-LDAP-without-losing-any-user/m-p/10393#M44</guid>
      <dc:creator>matt</dc:creator>
      <dc:date>2010-03-20T06:38:49Z</dc:date>
    </item>
    <item>
      <title>Re: How do I convert from basic auth to LDAP without losing any user data?</title>
      <link>https://community.splunk.com/t5/Security/How-do-I-convert-from-basic-auth-to-LDAP-without-losing-any-user/m-p/10394#M45</link>
      <description>&lt;P&gt;The easiest way to identify the local Splunkauth users is to check your $SPLUNK_HOME/etc/passwd file which is in the same format as unix passwd.  &lt;/P&gt;

&lt;P&gt;Figure out which of these users correspond to which LDAP users.&lt;/P&gt;

&lt;P&gt;Then locate your user's savedsearches and swap out the userid field with the corresponding ldap userid.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2010 12:23:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-I-convert-from-basic-auth-to-LDAP-without-losing-any-user/m-p/10394#M45</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2010-04-09T12:23:24Z</dc:date>
    </item>
    <item>
      <title>Re: How do I convert from basic auth to LDAP without losing any user data?</title>
      <link>https://community.splunk.com/t5/Security/How-do-I-convert-from-basic-auth-to-LDAP-without-losing-any-user/m-p/10395#M46</link>
      <description>&lt;P&gt;In versions 4.x, changing the userid field will only change the ownership of shared items. To make sure that private items are also connected to the old user, the contents of the directory &lt;CODE&gt;$SPLUNK_HOME/etc/users/olduserid&lt;/CODE&gt; must be copied or moved to &lt;CODE&gt;$SPLUNK_HOME/etc/users/newuserid&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Sun, 11 Apr 2010 21:12:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-I-convert-from-basic-auth-to-LDAP-without-losing-any-user/m-p/10395#M46</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-04-11T21:12:28Z</dc:date>
    </item>
  </channel>
</rss>

