Splunk Search
Highlighted

Search Head and LDAP

Path Finder

Does Search Head servers have anything more in common than which Indexer they are connected to? If I want two Search Heads to do LDAP authentication against the same AD I need to set it up the same way on both of the Search Heads? Or do they sync configuration in some way?

Is it also possible to set up two search heads authenticate against two different ADs but share the same Indexer servers? I guess this will cause some role and permission troubles when there are two different ADs. This would be great if customers want their own Search Head and authenticate against their own AD.

0 Karma
Highlighted

Re: Search Head and LDAP

Splunk Employee
Splunk Employee

With the current setup, search heads are totally independent. I believe it's in the roadmap to do more of a clustering setup, but for now, you just need to mirror your authentication.conf (and authorization.conf as appropriate). I'm not sure when the "cluster-esque" setup will arrive, though.

And yes, I don't think there should be any issues setting up different search heads to use totally different authentication schemes. It's probably best to test this out before investing too much time / money though 😉

Highlighted

Re: Search Head and LDAP

Splunk Employee
Splunk Employee

It's fine to use totally different auth on different search heads. The indexers do not know anything about authentication, as it is entirely managed by and delegated to the search head, so every search head can run independently. (From 4.2 on, they can be configured in a pool, but they don't have to be.)

0 Karma