<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Removed users from LDAP authentication but didn't remove them from Splunk users in Security</title>
    <link>https://community.splunk.com/t5/Security/Removed-users-from-LDAP-authentication-but-didn-t-remove-them/m-p/337168#M8612</link>
    <description>&lt;P&gt;Here's a docs article on that exact topic:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/6.6.3/Security/BestpracticeforremovinganLDAPuser"&gt;https://docs.splunk.com/Documentation/Splunk/6.6.3/Security/BestpracticeforremovinganLDAPuser&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 18 Sep 2017 00:34:58 GMT</pubDate>
    <dc:creator>brreeves_splunk</dc:creator>
    <dc:date>2017-09-18T00:34:58Z</dc:date>
    <item>
      <title>Removed users from LDAP authentication but didn't remove them from Splunk users</title>
      <link>https://community.splunk.com/t5/Security/Removed-users-from-LDAP-authentication-but-didn-t-remove-them/m-p/337164#M8608</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I see that there is documentation on this topic, but it is very unclear how it should be operating. So I am using LDAP authentication for Splunk and I removed a large group of users from my LDAP authentication step on a seperate application. However, this didn't remove the users from my list of splunk users. So I removed one specific user's folder in splunk/etc/users and the user is still not removed the splunk user list in UI. How should all of this functionality be working?&lt;/P&gt;

&lt;P&gt;If I remove the user from my LDAP authentication on my seperate app- will that user not be able to log in? Even though they are still listed a splunk user in my Access Controls- User list on the web?&lt;/P&gt;

&lt;P&gt;Thanks for the help!&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2017 20:19:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Removed-users-from-LDAP-authentication-but-didn-t-remove-them/m-p/337164#M8608</guid>
      <dc:creator>katzr</dc:creator>
      <dc:date>2017-09-15T20:19:22Z</dc:date>
    </item>
    <item>
      <title>Re: Removed users from LDAP authentication but didn't remove them from Splunk users</title>
      <link>https://community.splunk.com/t5/Security/Removed-users-from-LDAP-authentication-but-didn-t-remove-them/m-p/337165#M8609</link>
      <description>&lt;P&gt;-- So I am using LDAP authentication for Splunk and I removed a large group of users from my LDAP authentication step on a separate application.&lt;/P&gt;

&lt;P&gt;What does it mean?&lt;/P&gt;</description>
      <pubDate>Sat, 16 Sep 2017 11:39:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Removed-users-from-LDAP-authentication-but-didn-t-remove-them/m-p/337165#M8609</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-09-16T11:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: Removed users from LDAP authentication but didn't remove them from Splunk users</title>
      <link>https://community.splunk.com/t5/Security/Removed-users-from-LDAP-authentication-but-didn-t-remove-them/m-p/337166#M8610</link>
      <description>&lt;P&gt;I am assuming that you have removed a group from AD Users and computers. If so, try Load authentication in Splunk GUI on specific Search Head. It will remove the users from Splunk.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Sep 2017 17:44:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Removed-users-from-LDAP-authentication-but-didn-t-remove-them/m-p/337166#M8610</guid>
      <dc:creator>bsuresh1</dc:creator>
      <dc:date>2017-09-17T17:44:36Z</dc:date>
    </item>
    <item>
      <title>Re: Removed users from LDAP authentication but didn't remove them from Splunk users</title>
      <link>https://community.splunk.com/t5/Security/Removed-users-from-LDAP-authentication-but-didn-t-remove-them/m-p/337167#M8611</link>
      <description>&lt;P&gt;Hi katzr,&lt;/P&gt;

&lt;P&gt;If you remove or modify the group or user on the LDAP provider, you need to tell Splunk to reload the authentication using either this REST call&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; | rest splunk_server=* /services/authentication/providers/services/_reload
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;or this CLI Splunk command&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;./splunk _internal call /authentication/providers/services/_reload -auth
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will refresh/reload the LDAP provider information and your removed users/group should be gone.&lt;BR /&gt;
If the users/group is still visible, check with non-Splunk LDAP tools against the LDAP provider and see what you actually get back.&lt;/P&gt;

&lt;P&gt;Hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2017 00:25:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Removed-users-from-LDAP-authentication-but-didn-t-remove-them/m-p/337167#M8611</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2017-09-18T00:25:30Z</dc:date>
    </item>
    <item>
      <title>Re: Removed users from LDAP authentication but didn't remove them from Splunk users</title>
      <link>https://community.splunk.com/t5/Security/Removed-users-from-LDAP-authentication-but-didn-t-remove-them/m-p/337168#M8612</link>
      <description>&lt;P&gt;Here's a docs article on that exact topic:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/6.6.3/Security/BestpracticeforremovinganLDAPuser"&gt;https://docs.splunk.com/Documentation/Splunk/6.6.3/Security/BestpracticeforremovinganLDAPuser&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2017 00:34:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Removed-users-from-LDAP-authentication-but-didn-t-remove-them/m-p/337168#M8612</guid>
      <dc:creator>brreeves_splunk</dc:creator>
      <dc:date>2017-09-18T00:34:58Z</dc:date>
    </item>
  </channel>
</rss>

