Security

Using LDAP authentication, can I block access to a particular user in Splunk without removing them from the AD group?

jbsplunk
Splunk Employee
Splunk Employee

I'm using LDAP authentication with my Active Directory as my authentication method for Splunk. I need to stop a particular user from accessing Splunk, but I don't have access to the AD server. Is there some method I can use on the Splunk instance to block user access?

Tags (2)
1 Solution

Chubbybunny
Splunk Employee
Splunk Employee

a User base filter would the quickest way.

For example, an AD group named SplunkSF with the following user accounts assigned: user1, user2, and user3

With this User base filter (NOT), we can prevent user3 from gaining access to Splunk: LDAP connection settings > User Settings > User base filter

(!(sAMAccountName=user3))

Or prevent user1 and user3

(&(!(sAMAccountName=user1))(!(sAMAccountName=user3)))


(\__/)
(='.'=)
(")_(")

View solution in original post

Chubbybunny
Splunk Employee
Splunk Employee

a User base filter would the quickest way.

For example, an AD group named SplunkSF with the following user accounts assigned: user1, user2, and user3

With this User base filter (NOT), we can prevent user3 from gaining access to Splunk: LDAP connection settings > User Settings > User base filter

(!(sAMAccountName=user3))

Or prevent user1 and user3

(&(!(sAMAccountName=user1))(!(sAMAccountName=user3)))


(\__/)
(='.'=)
(")_(")

Chubbybunny
Splunk Employee
Splunk Employee

perhaps a enhancement request too, I would expect a kill switch to disable or block user access.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...