Is it possible to have ldap authentication and local authentication active? If so, how would I specify an account be local?
if you create a user with that method it will be a local user by default. Your ldap users will be auto-populated from your ldap directory based on your group mappings.
You'll need to create a new user it's under Access Controls - Users - Add New
Right, I see that, but where/how does it determine if it's an ldap authentication or local, if both are enabled?
You can't specify an ldap account to be local, you can however create a new local user on a system that has ldap already set.
Sorry, you lost me. I don't want an ldap account to be local, I just want the ability to specify that an account be local, via the splunk admin gui, but I don't see that option anywhere.