Security

Specifying multiple LDAP static group filters

aaronkorn
Splunk Employee
Splunk Employee

Is there a way to specify multiple group search filters for multiple groups? Currently we have this (sAMAccountName = ISD TSS Management) but is there a way to specify additional groups in this filter?

Tags (2)

3johnson
Engager

(CN=Splunk*)
This syntax worked fine for us to only display groups for mapping that begin with "Splunk"; but, the BIG difference is the groups have to be populated with users or Splunk produces a cryptic error stating that it can't find any groups with the search criteria. The better error would be that I can't find any groups WITH USERS IN IT with the search criteria. Limiting the DN of the group produces the same error if the group is empty.

It seems like a Splunk proces logic flaw. On every system for 25years the process is: Create Groups > Map Roles > Populate groups with users and test.
,(CN=Splunk*)
This syntax worked fine for us to only display groups for mapping that begin with "Splunk"; but, the BIG difference is the groups have to be populated with users or Splunk produces a cryptic error stating that it can't find any groups with the search criteria. The better error would be that I can't find any groups WITH USERS IN IT with the search criteria. Limiting the DN of the group produces the same error if the group is empty.

It seems like a Splunk proces logic flaw. On every system for 25years the process is: Create Groups > Map Roles > Populate groups with users and test.

dfronck
Communicator

LDAP "Group base DN"

OU=Corporate,OU=Groups,DC=OUR,DC=COMPANY,DC=COM

"Static group search filter"

(|(CN=Splunk*)(CN=UNIX*)(CN=WINTEL*))

This pulls all the groups starting with Splunk, UNIX and WINTEL.

You could also do something with wildcards.

(|(CN=Splunk*)(CN=*UNIX*)(CN=*WINTEL*))

This pulls all the groups starting with Splunk, and contains UNIX or WINTEL.

yungm
Engager

We specify multiple AD groups in "Group base DN" field under "Group settings" as 'cn=admingrp,ou=...;cn=usergrp,ou=...'. We do not use "Static group search filter.

The groups are then mapped to each local Splunk role for access control.

The "User base filter" is defined as follow:

(&(objectCategory=Person)(sAMAccountName=*))

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...