Splunk Search

Some AD groups are not displaying when setting up LDAP

DashZentin
Explorer

Hi all,

I have setup an LDAP connection to my AD server. But when I click on LDAP Groups, not all groups are displayed (missing 2 out of 5). I have no static group search filter.

The group that is missing has 1 user in. This user is in the same User base DN as the LDAP config (which also does not have a User base filter).

This is a brand new install. I want to assign that AD group the Admin role in Splunk.

I am using Splunk Enterprise 10.0.2 on Windows Server 2025.

Thank you for your help.

Labels (1)
0 Karma
1 Solution

DashZentin
Explorer

To answer my own question, the "Static member attribute" should be set to "member".

View solution in original post

PickleRick
SplunkTrust
SplunkTrust

That is very interesting since the latest released version is 10.0.2 so if you're using 10.0.4 you must be using time travel. Can I have lottery numbers for next week? 😉

But seriously - first things first - use a stand-alone LDAP client and perform the LDAP search for groups manually using the same user that Splunk is to be using. And check if you're getting all the groups as the result. If you do, you might start looking for issues in Splunk config, If you don't, you might have issues on the AD side - permissions problem?

0 Karma

DashZentin
Explorer

I used a ldp.exe (using the same bind DN as Splunk) and it returned the expected results (6 AD groups). Splunk only returns 3.

The Group Base DN: "ou=Splunk,ou=Application_Groups,ou=Security Groups,dc=office,dc=local"

The Group attribute name: "cn"

Static member attribute: "memberof"

User base DN: "ou=DomainUsers,dc=office,dc=local"

0 Karma

DashZentin
Explorer

To answer my own question, the "Static member attribute" should be set to "member".

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...