Security

LDAP Filter Adding Distinguished Name (DN)

ryan_t_gavin
New Member

We've been struggling to set up Splunk to use LDAP authentication for a while now. After finally getting it to bind successfully, it lists the groups when I map roles; however, when I log in as a user under a mapped role + group combo, it does not work. The DEBUG logs show the LDAP server returned no entries in search for DN="ou=Groups,dc=XXXX" filter="(&(memberuid=uid=XXXX,)(cn=*)"

A manual ldapsearch for the below does work:

ldapsearch -x -D "uid=XXXX,ou=XXX,dc=XXX" -W -H  -b "ou=XXX,dc=XXX" "(&(memberuid=XXXX)(cn=*))"

It LOOKS in the logs like Splunk is trying to do this equivalent search:

ldapsearch -x -D "uid=XXXX,ou=XXX,dc=XXX" -W -H  -b "ou=XXX,dc=XXX" "(&(memberuid=uid=XXXX,ou=XXX,dc=XXX)(cn=*))" 

Specifically, if it would just not put the DN in the filter, it should work. Any advice to get this working?

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...