Manage Splunk user roles with LDAP
To configure the Splunk platform to use LDAP authentication, you must first create a Splunk strategy for each LDAP server and then map Splunk roles to the groups on the LDAP server. When a user attempts to log in, the Splunk platform queries the servers to find the user. It grants the user permissions based on the roles that the user holds, based on what you have mapped to corresponding LDAP groups.
If you need to change the permissions that a user has, you have several options:
- To change the permissions for a group of users, you can remap the LDAP group to a different Splunk role. You can also update the role itself to specify a different set of permissions or capabilities for it. You do this on the Splunk platform.
- To change the permissions for an individual user, you can move the user to an LDAP group that you have mapped to a different Splunk role. You do this on the LDAP server.
Here are some example user management activities:
- To assign a Splunk role to a user: First, in Splunk Web, confirm that you've mapped the Splunk role to an LDAP group. Then, on your LDAP server, add the user to that LDAP group.
- To remove a Splunk role from a user: On your LDAP server, remove the user from the corresponding LDAP group.
A user can hold several roles. In that case, the user has access to all the capabilities available for those roles. For example, if the user is a member of both the docs and eng groups, and docs is mapped to "user" and eng is mapped to "admin", the user obtains all permissions assigned to both the "user" or "admin" roles.
The Splunk platform checks LDAP membership information when a user attempts to log in. You do not need to reload the authentication configuration when you add or remove users.
Set up user authentication with LDAP
LDAP prerequisites and considerations
This documentation applies to the following versions of Splunk Cloud Platform™: 8.2.2106, 8.2.2107, 8.2.2111, 8.2.2112, 8.2.2109, 8.2.2201, 8.2.2202, 8.2.2203, 9.0.2205, 9.0.2208, 9.0.2209 (latest FedRAMP release)