Security

Using LDAP authentication, can I block access to a particular user in Splunk without removing them from the AD group?

jbsplunk
Splunk Employee
Splunk Employee

I'm using LDAP authentication with my Active Directory as my authentication method for Splunk. I need to stop a particular user from accessing Splunk, but I don't have access to the AD server. Is there some method I can use on the Splunk instance to block user access?

Tags (2)
1 Solution

Chubbybunny
Splunk Employee
Splunk Employee

a User base filter would the quickest way.

For example, an AD group named SplunkSF with the following user accounts assigned: user1, user2, and user3

With this User base filter (NOT), we can prevent user3 from gaining access to Splunk: LDAP connection settings > User Settings > User base filter

(!(sAMAccountName=user3))

Or prevent user1 and user3

(&(!(sAMAccountName=user1))(!(sAMAccountName=user3)))


(\__/)
(='.'=)
(")_(")

View solution in original post

Chubbybunny
Splunk Employee
Splunk Employee

a User base filter would the quickest way.

For example, an AD group named SplunkSF with the following user accounts assigned: user1, user2, and user3

With this User base filter (NOT), we can prevent user3 from gaining access to Splunk: LDAP connection settings > User Settings > User base filter

(!(sAMAccountName=user3))

Or prevent user1 and user3

(&(!(sAMAccountName=user1))(!(sAMAccountName=user3)))


(\__/)
(='.'=)
(")_(")

Chubbybunny
Splunk Employee
Splunk Employee

perhaps a enhancement request too, I would expect a kill switch to disable or block user access.

0 Karma
Get Updates on the Splunk Community!

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...