Security

Default access when using LDAP authentication

micwhite
Explorer

I would like for anyone who successfully authenticates against LDAP to get a default level of access to Splunk. However, I don't have an "all users" group that I can map to a role defining this level of access. Is there a way achieve this?

Tags (1)
0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

There is a workaround in the docs (I think it will work, but haven't tried it).
http://docs.splunk.com/Documentation/Splunk/4.3.4/admin/SetUpUserauthenticationwithLDAP

Look under Configure LDAP through Splunk Web -> Create an LDAP Strategy -> Number 18.
The second bullet point takes note that not all environments have groups, so you can set the "group" to be a "user" and then assign a role based on that group. I haven't played with this at all, but might point you in the right direction.

0 Karma

micwhite
Explorer

Thanks. Thinking through this, as users logged in, I'd end up with a bunch of "~groups~". But how would they get mapped to a role? Would they get mapped to the user role by default?

0 Karma

deanilol
Explorer

Did you find an answer? I'm looking for exactly the same thing!!

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...