Security

Does Splunk not support LDAP group inheritance?

Glenn
Builder

The way LDAP and Active Directory group membership usually works is through inheritance - groups can be members of other groups, and these subgroups' members are then effectively members of the higher level group. Its tree structure and inheritance are one of the benefits of using LDAP.

I have just created two AD groups for Splunk, one with individual staff records as members, and the other with sub groups as members (in this case, our department/team groups that we use for access across all other apps). The latter is better, because it means that each time someone leaves or joins the team, the Splunk group does not have to be changed. It will just inherit the changes from the team groups.

However, Splunk does not seem to understand the inheritance - members of the first group are the only ones who are allowed to access the app that has been secured to these two groups. The others get the message "App "ig_pci" does not support UI access. See its app.conf for more information".

Does Splunk not support LDAP group inheritance?

1 Solution

the_wolverine
Champion

Correct, Splunk does not support nested groups currently. Splunk users will need to be a direct member of the LDAP group mapped to Splunk role.

View solution in original post

ithangasamy_spl
Splunk Employee
Splunk Employee

This feature is available in the forthcoming Splunk Release, you can request for a beta evaluation from the PMs now.

ithangasamy_spl
Splunk Employee
Splunk Employee

it would be 4.3

0 Karma

Glenn
Builder

Sweet, thanks for the update. That would be 4.2.4?

0 Karma

the_wolverine
Champion

Correct, Splunk does not support nested groups currently. Splunk users will need to be a direct member of the LDAP group mapped to Splunk role.

Glenn
Builder

I have had an enhancement request (45531) in for this functionality since Jul 8, 2010 7:08 AM (yes that's about 16 months).

It wastes a couple of hours of time for a few people in my organisation each week, due to them having to assign individual members (new starters) to the groups, rather than them automatically being included for appropriate access via their team's role group. Over the course of the last 2 years this probably adds up to quite a large operating cost!

Please include this enhancement soon. How can we get its priority raised?

the_wolverine
Champion

Yes, it is always worth filing an enhancement request for features that you would like to see in the product.

0 Karma

Glenn
Builder

Thanks. Do you think it is worth raising an enhancement request for it, or do you know if it already planned? It would make user management so much better if people could use their existing automatically managed team groups, rather than double handling.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...