<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LDAP with more then 1000 groups in Security</title>
    <link>https://community.splunk.com/t5/Security/LDAP-with-more-then-1000-groups/m-p/391489#M9564</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have a problem with a LDAP configuration I know there is a limit by 1000 users so I have change the following configuration&lt;/P&gt;

&lt;P&gt;authentication.conf&lt;BR /&gt;
sizelimit = 10000&lt;/P&gt;

&lt;P&gt;limits.conf&lt;BR /&gt;
[ldap]&lt;BR /&gt;
max_users_to_precache = 10000&lt;/P&gt;

&lt;P&gt;but it looks like this hasn´t impact of the max size of groups because it stops every time at 1000 groups.&lt;/P&gt;

&lt;P&gt;Any ideas what to do?&lt;/P&gt;

&lt;P&gt;Michel&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 20:03:16 GMT</pubDate>
    <dc:creator>michel_wolf</dc:creator>
    <dc:date>2020-09-29T20:03:16Z</dc:date>
    <item>
      <title>LDAP with more then 1000 groups</title>
      <link>https://community.splunk.com/t5/Security/LDAP-with-more-then-1000-groups/m-p/391489#M9564</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have a problem with a LDAP configuration I know there is a limit by 1000 users so I have change the following configuration&lt;/P&gt;

&lt;P&gt;authentication.conf&lt;BR /&gt;
sizelimit = 10000&lt;/P&gt;

&lt;P&gt;limits.conf&lt;BR /&gt;
[ldap]&lt;BR /&gt;
max_users_to_precache = 10000&lt;/P&gt;

&lt;P&gt;but it looks like this hasn´t impact of the max size of groups because it stops every time at 1000 groups.&lt;/P&gt;

&lt;P&gt;Any ideas what to do?&lt;/P&gt;

&lt;P&gt;Michel&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:03:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/LDAP-with-more-then-1000-groups/m-p/391489#M9564</guid>
      <dc:creator>michel_wolf</dc:creator>
      <dc:date>2020-09-29T20:03:16Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP with more then 1000 groups</title>
      <link>https://community.splunk.com/t5/Security/LDAP-with-more-then-1000-groups/m-p/391490#M9565</link>
      <description>&lt;P&gt;Have you tried&lt;/P&gt;

&lt;P&gt;groupBaseFilter = &lt;/P&gt;

&lt;P&gt;or in the GUI under Settings &amp;gt; Access Controls &amp;gt; Authentication method &amp;gt; LDAP settings &amp;gt; LDAP strategy name &amp;gt; Static group search filter &lt;/P&gt;

&lt;P&gt;The LDAP search filter used to retrieve static groups. Highly recommended if you have a large amount of group entries under your group base DN. For example, '(department=IT)'&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 22:13:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/LDAP-with-more-then-1000-groups/m-p/391490#M9565</guid>
      <dc:creator>jdhunter</dc:creator>
      <dc:date>2018-07-19T22:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP with more then 1000 groups</title>
      <link>https://community.splunk.com/t5/Security/LDAP-with-more-then-1000-groups/m-p/391491#M9566</link>
      <description>&lt;P&gt;what is group itself is having 5000 users? Filters will not work&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 14:38:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/LDAP-with-more-then-1000-groups/m-p/391491#M9566</guid>
      <dc:creator>waytoavnish</dc:creator>
      <dc:date>2019-03-26T14:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP with more then 1000 groups</title>
      <link>https://community.splunk.com/t5/Security/LDAP-with-more-then-1000-groups/m-p/391492#M9567</link>
      <description>&lt;P&gt;Any news on this?  I just ran into the same problem.&lt;/P&gt;

&lt;P&gt;We have more than 1000 groups.  The one I need to configure isn't in the first 1000 returned.   Perhaps if the 'Map Group' page used the search term to filter the query it sent to ldap?&lt;/P&gt;

&lt;P&gt;(the static group search term doesn't help, unless we go through and flag all the groups that might be used by Splunk with something, which isn't something I can manage soon.)&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2019 19:08:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/LDAP-with-more-then-1000-groups/m-p/391492#M9567</guid>
      <dc:creator>darkmoonvt</dc:creator>
      <dc:date>2019-05-09T19:08:35Z</dc:date>
    </item>
  </channel>
</rss>

