I have a splunk instance with ldap configuration. We noticed that huge number of authentications are being done on the LDAP service using the bind dn user. Does splunk authentication refresh the ldap strategies automatically every while? What could the reason behind the big number of authentications?
LDAP should be configured only on instances where users sign in-typically only search heads. Make sure your indexers don't have LDAP configured.
If you have a standalone Splunk instance, consider splitting it into separate SH and indexer.
--- If this reply helps you, an upvote would be appreciated.