<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic add ldap groups from database in Security</title>
    <link>https://community.splunk.com/t5/Security/add-ldap-groups-from-database/m-p/418358#M9946</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;im wondering if it is possible to add ldap group from db?&lt;/P&gt;

&lt;P&gt;i have some groups managed in db table and the it admin does not want to manage it is also in ldap (for splunk security and rules)&lt;BR /&gt;
im wondering if i can use the db table to manage rules in splunk ?&lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Tue, 11 Jun 2019 11:48:01 GMT</pubDate>
    <dc:creator>sarit_s</dc:creator>
    <dc:date>2019-06-11T11:48:01Z</dc:date>
    <item>
      <title>add ldap groups from database</title>
      <link>https://community.splunk.com/t5/Security/add-ldap-groups-from-database/m-p/418358#M9946</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;im wondering if it is possible to add ldap group from db?&lt;/P&gt;

&lt;P&gt;i have some groups managed in db table and the it admin does not want to manage it is also in ldap (for splunk security and rules)&lt;BR /&gt;
im wondering if i can use the db table to manage rules in splunk ?&lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 11:48:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/add-ldap-groups-from-database/m-p/418358#M9946</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2019-06-11T11:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: add ldap groups from database</title>
      <link>https://community.splunk.com/t5/Security/add-ldap-groups-from-database/m-p/418359#M9947</link>
      <description>&lt;P&gt;Can you add more context to your query here.&lt;BR /&gt;
Is this a kind of alternative you are trying for ldap auth in your Splunk OR you have some other purpose for them ?&lt;/P&gt;

&lt;P&gt;If its the auth, I'd like to hear more from you about how are you planning it ? If not, it'd be like any other DB table that can be ingested and managed through DBX app&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 18:36:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/add-ldap-groups-from-database/m-p/418359#M9947</guid>
      <dc:creator>amitm05</dc:creator>
      <dc:date>2019-06-11T18:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: add ldap groups from database</title>
      <link>https://community.splunk.com/t5/Security/add-ldap-groups-from-database/m-p/418360#M9948</link>
      <description>&lt;P&gt;Hey&lt;BR /&gt;
Yes, it is for ldap auth&lt;BR /&gt;
I have groups that managed in ldap today&lt;BR /&gt;
And i have to add some more groups that already managed in some db table&lt;BR /&gt;
The admin of that prefer not to manage this list of groups in both db table and ldap&lt;BR /&gt;
So i wondered if there is a way to take somehow the data from the table and add it to ldap so i will be able to manage splunk rules&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 21:08:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/add-ldap-groups-from-database/m-p/418360#M9948</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2019-06-11T21:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: add ldap groups from database</title>
      <link>https://community.splunk.com/t5/Security/add-ldap-groups-from-database/m-p/418361#M9949</link>
      <description>&lt;P&gt;Hi @sarit_s,&lt;/P&gt;

&lt;P&gt;The answer to your question is : "Use LDAP".. don't rely on another DB especially if it's not managed, maintained and supervised centrally by your security.&lt;/P&gt;

&lt;P&gt;So yes, recreate the groups from that database on your AD and just import them from there and map them as follows: &lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.0/Security/MapLDAPgroupstoSplunkroles"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.0/Security/MapLDAPgroupstoSplunkroles&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Cheers,&lt;BR /&gt;
David&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jun 2019 20:06:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/add-ldap-groups-from-database/m-p/418361#M9949</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-06-16T20:06:18Z</dc:date>
    </item>
  </channel>
</rss>

