Security
Highlighted

How to configure Splunk to authenticate through LDAP?

New Member

I am very new to Splunk. I am looking for a simplified document to help me configure Splunk to authenticate through LDAP. Is there such a document?

0 Karma
Highlighted

Re: How to configure Splunk to authenticate through LDAP?

Champion

Have you checked out the existing Splunk documentation for this?

http://docs.splunk.com/Documentation/Splunk/6.6.1/Security/SetupuserauthenticationwithLDAP

Highlighted

Re: How to configure Splunk to authenticate through LDAP?

Explorer

Here are the basic steps if you are doing this from the UI (you can also go to the CLI and update authentication.conf):

  1. From your search head, go to Settings > Access Controls > Authentication Method
  2. Select LDAP and click on Configure Splunk to use LDAP
  3. Click New, populate the required fields on the form and save.

If the connection to your LDAP host works, your strategy will be saved and you can then click on "Map Groups" to assign Splunk roles to you Active Directory groups.

Highlighted

Re: How to configure Splunk to authenticate through LDAP?

Path Finder
0 Karma
Highlighted

Re: How to configure Splunk to authenticate through LDAP?

Esteemed Legend

LDAP is tough. I would suggest 2 things:

1: Watch this video, by @ninja, IT ROCKS: https://youtu.be/JEo6dNXigBo
2: Test/experiment with the ldapsearchtool; install with sudo yum -y install openldap

0 Karma