Security

How to configure Splunk to authenticate through LDAP?

msg64
New Member

I am very new to Splunk. I am looking for a simplified document to help me configure Splunk to authenticate through LDAP. Is there such a document?

0 Karma

woodcock
Esteemed Legend

LDAP is tough. I would suggest 2 things:

1: Watch this video, by @ninja, IT ROCKS: https://youtu.be/JEo6dNXigBo
2: Test/experiment with the ldapsearchtool; install with sudo yum -y install openldap

jfeitosa_real
Path Finder
0 Karma

eagle4splunk
Explorer

Here are the basic steps if you are doing this from the UI (you can also go to the CLI and update authentication.conf):

  1. From your search head, go to Settings > Access Controls > Authentication Method
  2. Select LDAP and click on Configure Splunk to use LDAP
  3. Click New, populate the required fields on the form and save.

If the connection to your LDAP host works, your strategy will be saved and you can then click on "Map Groups" to assign Splunk roles to you Active Directory groups.

micahkemp
Champion

Have you checked out the existing Splunk documentation for this?

http://docs.splunk.com/Documentation/Splunk/6.6.1/Security/SetupuserauthenticationwithLDAP

Get Updates on the Splunk Community!

Now Playing: Splunk Education Summer Learning Premieres

It’s premiere season, and Splunk Education is rolling out new releases you won’t want to miss. Whether you’re ...

The Visibility Gap: Hybrid Networks and IT Services

The most forward thinking enterprises among us see their network as much more than infrastructure – it's their ...

Get Operational Insights Quickly with Natural Language on the Splunk Platform

In today’s fast-paced digital world, turning data into actionable insights is essential for success. With ...