in the following page, i can see list of users in splunk.
I see a field called Email address and we use LDAP authentication. I would like to configure splunk so that i can see user's email id auto populated from AD
my setting in authentication.conf
authSettings = AD,AD1
authType = LDAP
This question has been around since at least May 2010 v4.1. http://splunk-base.splunk.com/answers/2138/ldap-authenticated-users-do-not-pick-up-mail-attribute-fr...
I'm on 5.0.3 and it looks like email addresses still can't be automatically pulled from AD and they can't even be added manually!
It should be pretty simple to add this feature.
A stop gap solution would be to pull from your AD or LDAP a .csv file containing username and email address. This can be uploaded as a lookup table and used in searches for internal and audit indexes. It doesn't put the emails where you want them but you'll have a way of accessing them for reporting or alerting.