<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User Mapping in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/User-Mapping/m-p/540017#M4950</link>
    <description>&lt;P&gt;authorize.conf is used for mapping capabilities to roles&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.2/Admin/authorizeconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.2/Admin/authorizeconf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 15 Feb 2021 20:17:01 GMT</pubDate>
    <dc:creator>edwardrose</dc:creator>
    <dc:date>2021-02-15T20:17:01Z</dc:date>
    <item>
      <title>User Mapping</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/User-Mapping/m-p/540001#M4944</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to find where a user is getting mapped to a role.&amp;nbsp; I can see that the user is mapped to the power role in the webui, but I do not see the user being mapped there in /opt/splunk/etc/system/local/authentication.conf.&amp;nbsp; So what am I missing?&amp;nbsp; Also there is nothing in /opt/splunk/etc/apps/* that would map the user to the power role.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thoughts?&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;ed&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2021 17:41:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/User-Mapping/m-p/540001#M4944</guid>
      <dc:creator>edwardrose</dc:creator>
      <dc:date>2021-02-15T17:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: User Mapping</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/User-Mapping/m-p/540017#M4950</link>
      <description>&lt;P&gt;authorize.conf is used for mapping capabilities to roles&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.2/Admin/authorizeconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.2/Admin/authorizeconf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2021 20:17:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/User-Mapping/m-p/540017#M4950</guid>
      <dc:creator>edwardrose</dc:creator>
      <dc:date>2021-02-15T20:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: User Mapping</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/User-Mapping/m-p/540038#M4951</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/166292"&gt;@edwardrose&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;User role mappings are in below file;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;$SPLUNK_HOME/etc/passwd&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 03:36:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/User-Mapping/m-p/540038#M4951</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-02-16T03:36:37Z</dc:date>
    </item>
    <item>
      <title>Re: User Mapping</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/User-Mapping/m-p/540096#M4964</link>
      <description>&lt;P&gt;&lt;STRIKE&gt;There is no role mapping info in the passwd file,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt;&amp;nbsp;&lt;/STRIKE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 18:40:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/User-Mapping/m-p/540096#M4964</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-02-16T18:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: User Mapping</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/User-Mapping/m-p/540114#M4967</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Inside $SPLUNK_HOME/etc/passwd below bold field is user role for local Splun authentication.&amp;nbsp;If user has more roles they are listed there comma separated.&lt;/P&gt;&lt;P&gt;:admin:password_hash::Administrator:&lt;STRONG&gt;admin&lt;/STRONG&gt;:changeme@example.com:::18624&lt;/P&gt;&lt;P&gt;In case of LDAP authentication user -&amp;gt; role mapping is in authentication.conf&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 14:58:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/User-Mapping/m-p/540114#M4967</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-02-16T14:58:02Z</dc:date>
    </item>
    <item>
      <title>Re: User Mapping</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/User-Mapping/m-p/540145#M4969</link>
      <description>&lt;P&gt;Thanks for straightening me out,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt;&amp;nbsp;.&amp;nbsp; I ran a quick test and the mapping of user to role(s) is indeed in passwd.&amp;nbsp; Authorize.conf maps the roles to capabilities and other settings.&lt;/P&gt;&lt;P&gt;I'll remove my erroneous answer to avoid confusion.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 18:39:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/User-Mapping/m-p/540145#M4969</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-02-16T18:39:02Z</dc:date>
    </item>
  </channel>
</rss>

