- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Specifying multiple LDAP static group filters

- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
(CN=Splunk*)
This syntax worked fine for us to only display groups for mapping that begin with "Splunk"; but, the BIG difference is the groups have to be populated with users or Splunk produces a cryptic error stating that it can't find any groups with the search criteria. The better error would be that I can't find any groups WITH USERS IN IT with the search criteria. Limiting the DN of the group produces the same error if the group is empty.
It seems like a Splunk proces logic flaw. On every system for 25years the process is: Create Groups > Map Roles > Populate groups with users and test.
,(CN=Splunk*)
This syntax worked fine for us to only display groups for mapping that begin with "Splunk"; but, the BIG difference is the groups have to be populated with users or Splunk produces a cryptic error stating that it can't find any groups with the search criteria. The better error would be that I can't find any groups WITH USERS IN IT with the search criteria. Limiting the DN of the group produces the same error if the group is empty.
It seems like a Splunk proces logic flaw. On every system for 25years the process is: Create Groups > Map Roles > Populate groups with users and test.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

LDAP "Group base DN"
OU=Corporate,OU=Groups,DC=OUR,DC=COMPANY,DC=COM
"Static group search filter"
(|(CN=Splunk*)(CN=UNIX*)(CN=WINTEL*))
This pulls all the groups starting with Splunk, UNIX and WINTEL.
You could also do something with wildcards.
(|(CN=Splunk*)(CN=*UNIX*)(CN=*WINTEL*))
This pulls all the groups starting with Splunk, and contains UNIX or WINTEL.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We specify multiple AD groups in "Group base DN" field under "Group settings" as 'cn=admingrp,ou=...;cn=usergrp,ou=...'. We do not use "Static group search filter.
The groups are then mapped to each local Splunk role for access control.
The "User base filter" is defined as follow:
(&(objectCategory=Person)(sAMAccountName=*))
