Security

Using LDAP authentication, can I block access to a particular user in Splunk without removing them from the AD group?

jbsplunk
Splunk Employee
Splunk Employee

I'm using LDAP authentication with my Active Directory as my authentication method for Splunk. I need to stop a particular user from accessing Splunk, but I don't have access to the AD server. Is there some method I can use on the Splunk instance to block user access?

Tags (2)
1 Solution

Chubbybunny
Splunk Employee
Splunk Employee

a User base filter would the quickest way.

For example, an AD group named SplunkSF with the following user accounts assigned: user1, user2, and user3

With this User base filter (NOT), we can prevent user3 from gaining access to Splunk: LDAP connection settings > User Settings > User base filter

(!(sAMAccountName=user3))

Or prevent user1 and user3

(&(!(sAMAccountName=user1))(!(sAMAccountName=user3)))


(\__/)
(='.'=)
(")_(")

View solution in original post

Chubbybunny
Splunk Employee
Splunk Employee

a User base filter would the quickest way.

For example, an AD group named SplunkSF with the following user accounts assigned: user1, user2, and user3

With this User base filter (NOT), we can prevent user3 from gaining access to Splunk: LDAP connection settings > User Settings > User base filter

(!(sAMAccountName=user3))

Or prevent user1 and user3

(&(!(sAMAccountName=user1))(!(sAMAccountName=user3)))


(\__/)
(='.'=)
(")_(")

Chubbybunny
Splunk Employee
Splunk Employee

perhaps a enhancement request too, I would expect a kill switch to disable or block user access.

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...