Security

Default access when using LDAP authentication

micwhite
Explorer

I would like for anyone who successfully authenticates against LDAP to get a default level of access to Splunk. However, I don't have an "all users" group that I can map to a role defining this level of access. Is there a way achieve this?

Tags (1)
0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

There is a workaround in the docs (I think it will work, but haven't tried it).
http://docs.splunk.com/Documentation/Splunk/4.3.4/admin/SetUpUserauthenticationwithLDAP

Look under Configure LDAP through Splunk Web -> Create an LDAP Strategy -> Number 18.
The second bullet point takes note that not all environments have groups, so you can set the "group" to be a "user" and then assign a role based on that group. I haven't played with this at all, but might point you in the right direction.

0 Karma

micwhite
Explorer

Thanks. Thinking through this, as users logged in, I'd end up with a bunch of "~groups~". But how would they get mapped to a role? Would they get mapped to the user role by default?

0 Karma

deanilol
Explorer

Did you find an answer? I'm looking for exactly the same thing!!

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...