Security

Splunk LDAP sending huge number of searches every day

ad077
New Member

I have a splunk instance with ldap configuration.
We noticed that huge number of authentications are being done on the LDAP service using the bind dn user.
Does splunk authentication refresh the ldap strategies automatically every while?
What could the reason behind the big number of authentications?

Labels (1)
Tags (2)
0 Karma

PavelP
Motivator

this can be some ldapseach command or script which is called for each result. Check if you have any of following apps/add-ons installed, and if yes, check where are they used:

  • add-on-for-ldap TA-LDAP
  • dashboard-use-cases-for-ta-ldap DA-LDAP
  • OpenLDAP Add-on for Splunk Splunk_TA_openldap
  • python-ldap-technology-add-on TA-pyLDAP
  • splunk_app_aws
0 Karma

richgalloway
SplunkTrust
SplunkTrust

LDAP should be configured only on instances where users sign in-typically only search heads. Make sure your indexers don't have LDAP configured.
If you have a standalone Splunk instance, consider splitting it into separate SH and indexer.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...