Security

How do I get LDAP values from Active Directory?

matt
Splunk Employee
Splunk Employee

I need to figure out what LDAP values I should be using to make auth work.

2 Solutions

matt
Splunk Employee
Splunk Employee

If you are comfortable with the command line you can run the command ldifede. The ldifde command is the windows equivalent of ldapsearch and should allow you to get an ldif entry for yourself and a group. With those two entries we should be able to come up with authentication.conf that will allow Splunk to authenticate users.

If you are more comfortable with a GUI The Sysinternals team offers a nice utility called Active Directory Explorer. This gives you tree view of your Active Directory/LDAP structure similar to Windows Explorer.

Both "LDP" and "ADSIEDIT.MSC" are built in utilities that allow you to have a GUI view of Active Directory. Run them from "Start--> Run" in Windows on your AD Server

The values that you will need to map are:

BindDN: This will be the full Distinguised Name of the user that Splunk is going to connect to the AD server as

UserBaseDN: Look at the Distinguished name for the user that you got from ldifde and take everything after cn=foo

GroupBaseDN: Look at the Distinguished name for the group that you got from ldifde and take everything after cn=foo

Real name attribute: Look for the key that is associated with the full name of the user (likely displayName)

Group name attribute: Look for the key that is associated with the full name of the group (likely cn)

Group member attribute: Its usually memberOf or member, depending on whether the memberships are listed in the group entry or the user entry

You may also want to check out this video from the Splunk Ninja

View solution in original post

benstraw
Splunk Employee
Splunk Employee

There are good examples for using ldif and ldapsearch on the splunk documentation. http://docs.splunk.com/Documentation/Splunk/5.0/Security/SetupuserauthenticationwithLDAP

View solution in original post

the_wolverine
Champion

Another great (freeware) LDAP browser is Apache Directory Studio. You can download builds for OSX, Linux and Windows.

benstraw
Splunk Employee
Splunk Employee

There are good examples for using ldif and ldapsearch on the splunk documentation. http://docs.splunk.com/Documentation/Splunk/5.0/Security/SetupuserauthenticationwithLDAP

matt
Splunk Employee
Splunk Employee

If you are comfortable with the command line you can run the command ldifede. The ldifde command is the windows equivalent of ldapsearch and should allow you to get an ldif entry for yourself and a group. With those two entries we should be able to come up with authentication.conf that will allow Splunk to authenticate users.

If you are more comfortable with a GUI The Sysinternals team offers a nice utility called Active Directory Explorer. This gives you tree view of your Active Directory/LDAP structure similar to Windows Explorer.

Both "LDP" and "ADSIEDIT.MSC" are built in utilities that allow you to have a GUI view of Active Directory. Run them from "Start--> Run" in Windows on your AD Server

The values that you will need to map are:

BindDN: This will be the full Distinguised Name of the user that Splunk is going to connect to the AD server as

UserBaseDN: Look at the Distinguished name for the user that you got from ldifde and take everything after cn=foo

GroupBaseDN: Look at the Distinguished name for the group that you got from ldifde and take everything after cn=foo

Real name attribute: Look for the key that is associated with the full name of the user (likely displayName)

Group name attribute: Look for the key that is associated with the full name of the group (likely cn)

Group member attribute: Its usually memberOf or member, depending on whether the memberships are listed in the group entry or the user entry

You may also want to check out this video from the Splunk Ninja

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...