Splunk Search

LDAP group reporting

aoliullah
Path Finder

Hi. Could someone suggest how I could go about creating a report that list all AD users and all the associated LDAP groups they belong to? This is required for audit purposes and tips on any other way of presenting the info would also be appreciated. Ideally I want a list that shows every AD group or may be just the privileged group a user account is part of.

Thanks in advance.

0 Karma
1 Solution

brreeves_splunk
Splunk Employee
Splunk Employee

You could use something like this if you have SA-ldapsearch installed:

| ldapsearch search="(&(objectClass=user)(!(objectClass=computer)))" attrs=* | table sAMAccountName memberOf

https://splunkbase.splunk.com/app/1151/

View solution in original post

brreeves_splunk
Splunk Employee
Splunk Employee

You could use something like this if you have SA-ldapsearch installed:

| ldapsearch search="(&(objectClass=user)(!(objectClass=computer)))" attrs=* | table sAMAccountName memberOf

https://splunkbase.splunk.com/app/1151/

aoliullah
Path Finder

Hi brreeves. Thanks for the answer. I shall try this and get back to you if need be.

0 Karma

aoliullah
Path Finder

Hi Breeves. For this to work will the search head need to be a windows box? Or does any other instance need to be a windows box to query AD?

0 Karma

brreeves_splunk
Splunk Employee
Splunk Employee

No, You'll just load the Splunk Support for Active Directory app and tell it where your AD servers are (it supports linux and windows, as it uses scripts to query AD). Then run the search and Splunk will query AD.

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...