How to use email or User Principle Name (UPN) instead of the Active Directory login?

Path Finder

We currently have our users log into Splunk using their Active Directory (AD) credentials, and specifically the SamAccountName field. In the LDAP strategies pane, there is an option for changing this field. I would like to use email or User Principle Name (UPN). Has anyone done this, and does it present a problem?


0 Karma

Splunk Employee
Splunk Employee

Yes, you can set authentication.conf > userNameAttribute to either "mail" or "userPrincipalName" and login with either.

In my test setup (which I confirmed this in), my email address is the username for both, and after setting it to the respective values, I was able to log in both times.

Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...

Security Newsletter Updates | March 2023

 March 2023 | Check out the latest and greatestUnify Your Security Operations with Splunk Mission Control The ...