Dashboards & Visualizations

How to display the status of an account in Splunk UI as disabled when they have been disabled in LDAP?

slicedtechsuppo
Engager

We are currently auditing the OSB Splunk user access accounts for both of our instances.

Unfortunately Splunk doesn't show or display under its user settings when an account has been disabled from LDAP (at the moment all the accounts are shown as 'Active'). Also, since user authentication has been configured by using LDAP, can you please confirm or advise why is not possible to display the status of an account in Splunk UI as disabled when they have been disabled in LDAP?

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk is not synchronized with the LDAP provider so it will not necessarily show the same status as the provider.  The LDAP config is only used during login to authenticate the user and get the group(s) to which they are a member.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...

Out of the Box to Up And Running - Streamlined Observability for Your Cloud ...

  Tech Talk Streamlined Observability for Your Cloud Environment Register    Out of the Box to Up And Running ...

Splunk Smartness with Brandon Sternfield | Episode 3

Hello and welcome to another episode of "Splunk Smartness," the interview series where we explore the power of ...