Security

User authentication to multiple AD domains in Splunk

joberget
Path Finder

Is it possible to configure Splunk so that one can choose which Active Directory to login in to? For example in the login menu of Splunk web choose which AD I want to login to.

Tags (2)

Jason
Motivator

This is now possible (beginning with Splunk 5 in late 2012). You can configure mutiple LDAP servers and Splunk will try each one. The current limitation seems to be that the user must be able to authenticate and be in a splunk-role-assigned group on the same LDAP server ("scheme").

http://docs.splunk.com/Documentation/Splunk/latest/Security/ConfigureSplunkwithmultipleLDAPservers

0 Karma

mpatnode
Path Finder

This could be done using another (free) product:

  1. Install Splunk on a Linux machine

  2. Install Centrify Express on that same machine.

  3. Join one of the domains

  4. Configure Splunk for PAM authentication.

Now, assuming the domains are in the same forest, or you have cross-forest trust between the domains, users can log into Splunk as [email protected].

0 Karma

joberget
Path Finder

Thanks! I will check Centrify Express out.

0 Karma

joberget
Path Finder

Thanks for the reply! I will fill an ER as soon as we become Enterprise customers. 🙂

0 Karma

the_wolverine
Champion

This is not currently possible, unfortunately. Other folks have asked for this feature and I believe it will come in a future release. If you're an Enterprise customer please file an ER to request it to help us gauge the interest.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...