Using LDAP for authentication

By default, Splunk authenticates using its own authentication system, which simply stores users and roles in flat files. The other two options available are LDAP and scripted authentication.

Note: that Free versions of Splunk do not support these options for authentication.

To enable LDAP authentication, perform the following steps:

  1. Navigate to Settings | Access controls | Authentication method
  2. Check the LDAP checkbox
  3. Click on Configure Splunk to use LDAP and map groups
  4. Click on New

You will then need the appropriate values to set up access to your LDAP server.

Every organization sets up LDAP slightly differently, so I have never managed to configure this properly the first time. Your best bet is to copy the ...

Get Implementing Splunk 7 - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.