Splunk Search

Ldap Command line works -- Web-UI does not work

ranmanh
New Member

Hi

This is for splunk version 4.3.4, build 136012

I have setup ldap authentication in file : /opt/splunk/etc/system/local/authentication.conf
And looking at the splunkd.log everything seems fine. I can see the LDAP credentials and users being cached. I have tested to reload splunk using the LDAP credentials from the command line and everything works perfectly fine.

Now, THis does NOT work in the web-ui. I cannot log in there using the ldap credentials.
I have tried: Manager » Access controls » Authentication method --> LDAP (as that was inactive)
then : Configure Splunk to use LDAP and map groups (my strategy was there)
and ENABLE it as it looked disabled.
In the end I have "Reload authentication configuration" , even I have restarted the server but I cannot log into the web-ui using the LDAP credentials.

Any idea what I might be missing?

Thanks

Tags (1)
0 Karma

ranmanh
New Member

In the end it was working all right!! Silly issue with a typo!

0 Karma
Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...