Splunk Search

Search Head and LDAP

joberget
Path Finder

Does Search Head servers have anything more in common than which Indexer they are connected to? If I want two Search Heads to do LDAP authentication against the same AD I need to set it up the same way on both of the Search Heads? Or do they sync configuration in some way?

Is it also possible to set up two search heads authenticate against two different ADs but share the same Indexer servers? I guess this will cause some role and permission troubles when there are two different ADs. This would be great if customers want their own Search Head and authenticate against their own AD.

0 Karma

David
Splunk Employee
Splunk Employee

With the current setup, search heads are totally independent. I believe it's in the roadmap to do more of a clustering setup, but for now, you just need to mirror your authentication.conf (and authorization.conf as appropriate). I'm not sure when the "cluster-esque" setup will arrive, though.

And yes, I don't think there should be any issues setting up different search heads to use totally different authentication schemes. It's probably best to test this out before investing too much time / money though 😉

gkanapathy
Splunk Employee
Splunk Employee

It's fine to use totally different auth on different search heads. The indexers do not know anything about authentication, as it is entirely managed by and delegated to the search head, so every search head can run independently. (From 4.2 on, they can be configured in a pool, but they don't have to be.)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...

Join the Final Session of the Data Management & Federation Bootcamp Series

Over the past three sessions of the Data Management & Federation Bootcamp Series, we've explored how to build ...

From Data to Insight: Announcing the Winners of the Splunk Dashboard Contest

Hi Splunkers, First off, thank you to everyone who participated in our very first From Data to Insight: The ...