Security

add ldap groups from database

sarit_s
Communicator

Hello

im wondering if it is possible to add ldap group from db?

i have some groups managed in db table and the it admin does not want to manage it is also in ldap (for splunk security and rules)
im wondering if i can use the db table to manage rules in splunk ?

thanks

Tags (2)
0 Karma
1 Solution

DavidHourani
Super Champion

Hi @sarit_s,

The answer to your question is : "Use LDAP".. don't rely on another DB especially if it's not managed, maintained and supervised centrally by your security.

So yes, recreate the groups from that database on your AD and just import them from there and map them as follows:
https://docs.splunk.com/Documentation/Splunk/7.3.0/Security/MapLDAPgroupstoSplunkroles

Cheers,
David

View solution in original post

DavidHourani
Super Champion

Hi @sarit_s,

The answer to your question is : "Use LDAP".. don't rely on another DB especially if it's not managed, maintained and supervised centrally by your security.

So yes, recreate the groups from that database on your AD and just import them from there and map them as follows:
https://docs.splunk.com/Documentation/Splunk/7.3.0/Security/MapLDAPgroupstoSplunkroles

Cheers,
David

amitm05
Builder

Can you add more context to your query here.
Is this a kind of alternative you are trying for ldap auth in your Splunk OR you have some other purpose for them ?

If its the auth, I'd like to hear more from you about how are you planning it ? If not, it'd be like any other DB table that can be ingested and managed through DBX app

0 Karma

sarit_s
Communicator

Hey
Yes, it is for ldap auth
I have groups that managed in ldap today
And i have to add some more groups that already managed in some db table
The admin of that prefer not to manage this list of groups in both db table and ldap
So i wondered if there is a way to take somehow the data from the table and add it to ldap so i will be able to manage splunk rules

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Drivers: How We're Streaming Real-Time F1 Telemetry Directly into Splunk ...

Data Drivers: Every Lap Tells a Story The Spectacle Two F1 racing sims go head-to-head on the .conf26 show ...

Data Management Digest – July 2026

  Welcome to the July 2026 edition of Data Management Digest! As your trusted partner in data innovation, the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...