Does anyone know if Splunk Enterprise Security supports Active Directory (or LDAP) for authentication, version 2008-R2 / 2012?
Splunk Enterprise supports Windows AD / LDAP authentication for User and Group mappings.
See here : http://docs.splunk.com/Documentation/Splunk/6.3.2/Security/SetupuserauthenticationwithLDAP
Are you referring to authentication to the Splunk platform itself, or ingesting data from AD to populate identities in Enterprise Security?