Security

Default access when using LDAP authentication

micwhite
Explorer

I would like for anyone who successfully authenticates against LDAP to get a default level of access to Splunk. However, I don't have an "all users" group that I can map to a role defining this level of access. Is there a way achieve this?

Tags (1)
0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

There is a workaround in the docs (I think it will work, but haven't tried it).
http://docs.splunk.com/Documentation/Splunk/4.3.4/admin/SetUpUserauthenticationwithLDAP

Look under Configure LDAP through Splunk Web -> Create an LDAP Strategy -> Number 18.
The second bullet point takes note that not all environments have groups, so you can set the "group" to be a "user" and then assign a role based on that group. I haven't played with this at all, but might point you in the right direction.

0 Karma

micwhite
Explorer

Thanks. Thinking through this, as users logged in, I'd end up with a bunch of "~groups~". But how would they get mapped to a role? Would they get mapped to the user role by default?

0 Karma

deanilol
Explorer

Did you find an answer? I'm looking for exactly the same thing!!

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...