Reporting

How to get email id from LDAP

ma_anand1984
Contributor

in the following page, i can see list of users in splunk.
/manager/search/authentication/users

I see a field called Email address and we use LDAP authentication. I would like to configure splunk so that i can see user's email id auto populated from AD

my setting in authentication.conf
[authentication]
authSettings = AD,AD1
authType = LDAP

Anand

dfronck
Communicator

We just upgraded to v6.2.1 and the Email Addresses are now being populated by LDAP.

jluste
Path Finder

A stop gap solution would be to pull from your AD or LDAP a .csv file containing username and email address. This can be uploaded as a lookup table and used in searches for internal and audit indexes. It doesn't put the emails where you want them but you'll have a way of accessing them for reporting or alerting.

gavin1_davenpor
Path Finder

This is a bit of a showstopper - how are we supposed to populate email addresses ??

dfronck
Communicator

This question has been around since at least May 2010 v4.1. http://splunk-base.splunk.com/answers/2138/ldap-authenticated-users-do-not-pick-up-mail-attribute-fr...

I'm on 5.0.3 and it looks like email addresses still can't be automatically pulled from AD and they can't even be added manually!

It should be pretty simple to add this feature.

ma_anand1984
Contributor

i have put in a feature request with splunk. They told me that they will add it. No SLA though

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...