Security

Why are new users accounts using LDAP and established groups not appearing in Splunk?

cjsweeney1
Explorer

After having system admin create new Active Directory account and asking to be put in establish Splunk group (along with other established, working accounts) the new user is not showing up in the Splunk user area. Anyone know what I should verify or look at? I would think it would just pop up on the screen at that point.

0 Karma

smiejascott
New Member

My solution was to go into the LDAP mapping for the updated group, check to see that the new user was listed, and save the change. The user then appeared in the user list.

The path to the group mapping is:
Access controls » Authentication method » LDAP strategies

0 Karma

brreeves_splunk
Splunk Employee
Splunk Employee

Is the user who is not showing up able to log in?

What version of Splunk?

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...