Alerting

LDAP authenticated users do not pick up mail attribute from AD?

jeff
Contributor

Splunk 4.1. I configured LDAP authentication, pointing to our AD domain controller. The users get mapped to roles successfully, but I examine the user's attributes under Manager>>Access controls>>Users>>juser, Email address is blank (and uneditable). The user is also unable to edit their own email preferences.

How can I enable emailed alerts/reports for these users?

Tags (3)
1 Solution

the_wolverine
Champion

Scheduled alerts are configurable by the Splunk user. The alerts can be configured to send email to any email address and Splunk does not assume that the configured alert is sent to the user who created the alert.

Currently Splunk does not provide the built-in capability to map the email attribute. If you have a use-case for this, feel free to file an Enhancement Request.

View solution in original post

jspears
Communicator

In 4.3 there appears to be a default option to email a link to the results of backgrounded searches when they complete. Presently on our system, only admin can take advantage of this capability because normal users are all in LDAP, with no way to populate their email field. So by opting to use LDAP authentication, we're missing out on some nice functionality in the core product.

the_wolverine
Champion

Yes this is definitely a very nice feature to have for any user who is backgrounding searches.

0 Karma

the_wolverine
Champion

Scheduled alerts are configurable by the Splunk user. The alerts can be configured to send email to any email address and Splunk does not assume that the configured alert is sent to the user who created the alert.

Currently Splunk does not provide the built-in capability to map the email attribute. If you have a use-case for this, feel free to file an Enhancement Request.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...