Splunk Search

Some AD groups are not displaying when setting up LDAP

DashZentin
Engager

Hi all,

I have setup an LDAP connection to my AD server. But when I click on LDAP Groups, not all groups are displayed (missing 2 out of 5). I have no static group search filter.

The group that is missing has 1 user in. This user is in the same User base DN as the LDAP config (which also does not have a User base filter).

This is a brand new install. I want to assign that AD group the Admin role in Splunk.

I am using Splunk Enterprise 10.0.2 on Windows Server 2025.

Thank you for your help.

Labels (1)
0 Karma
1 Solution

DashZentin
Engager

To answer my own question, the "Static member attribute" should be set to "member".

View solution in original post

PickleRick
SplunkTrust
SplunkTrust

That is very interesting since the latest released version is 10.0.2 so if you're using 10.0.4 you must be using time travel. Can I have lottery numbers for next week? 😉

But seriously - first things first - use a stand-alone LDAP client and perform the LDAP search for groups manually using the same user that Splunk is to be using. And check if you're getting all the groups as the result. If you do, you might start looking for issues in Splunk config, If you don't, you might have issues on the AD side - permissions problem?

0 Karma

DashZentin
Engager

I used a ldp.exe (using the same bind DN as Splunk) and it returned the expected results (6 AD groups). Splunk only returns 3.

The Group Base DN: "ou=Splunk,ou=Application_Groups,ou=Security Groups,dc=office,dc=local"

The Group attribute name: "cn"

Static member attribute: "memberof"

User base DN: "ou=DomainUsers,dc=office,dc=local"

0 Karma

DashZentin
Engager

To answer my own question, the "Static member attribute" should be set to "member".

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...