Splunk Search

Search Head and LDAP

joberget
Path Finder

Does Search Head servers have anything more in common than which Indexer they are connected to? If I want two Search Heads to do LDAP authentication against the same AD I need to set it up the same way on both of the Search Heads? Or do they sync configuration in some way?

Is it also possible to set up two search heads authenticate against two different ADs but share the same Indexer servers? I guess this will cause some role and permission troubles when there are two different ADs. This would be great if customers want their own Search Head and authenticate against their own AD.

0 Karma

David
Splunk Employee
Splunk Employee

With the current setup, search heads are totally independent. I believe it's in the roadmap to do more of a clustering setup, but for now, you just need to mirror your authentication.conf (and authorization.conf as appropriate). I'm not sure when the "cluster-esque" setup will arrive, though.

And yes, I don't think there should be any issues setting up different search heads to use totally different authentication schemes. It's probably best to test this out before investing too much time / money though 😉

gkanapathy
Splunk Employee
Splunk Employee

It's fine to use totally different auth on different search heads. The indexers do not know anything about authentication, as it is entirely managed by and delegated to the search head, so every search head can run independently. (From 4.2 on, they can be configured in a pool, but they don't have to be.)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Supercharging Windows Security Detection Performance: Introducing Hybrid Field ...

Windows event logs—from Security auditing and Sysmon to PowerShell script blocks—form the operational backbone ...

Ditch the Manual Grind: Building AI Agents with Splunk

Ditch the Manual Grind: Building AI Agents with Splunk Let’s be real: your team’s time is being eaten alive. ...

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...