---
title: Configuring Splunk Access Controls with LDAP
description: Configuring Splunk Access Controls with LDAP
image: https://blog.augustschell.com/hubfs/configuring-splunk.jpg
---

[Skip to content](https://blog.augustschell.com/configuring-splunk-access-controls-ldap#main-content)

[![August Schell Logo](https://blog.augustschell.com/hubfs/ase-logo-2022-color-notag.svg "August Schell Logo")](http://augustschell.com)

- [Services](https://augustschell.com/services/)
  
  Show submenu for Services 
  
    - [Professional Services Offerings](https://augustschell.com/services-offering/)
- Solutions
  
  Show submenu for Solutions 
  
    - [Security](https://augustschell.com/home-security-solutions/)
    - [Big Data](https://augustschell.com/home-solutions-data/)
- [Resources](https://augustschell.com/resources/)
- [Company](https://augustschell.com/about-us/)
  
  Show submenu for Company 
  
    - [Customers](https://augustschell.com/customers/)
    - [Partners](https://augustschell.com/partners/)
    - [Joint Ventures](https://augustschell.com/home-company-joint-ventures/)
    - [Contracts](https://augustschell.com/contracts-2/)
    - [Where to Find Us](https://augustschell.com/home-company-news/)
    - [About Us](https://augustschell.com/about/)
    - [Contact](https://augustschell.com/contact/)
- [Quotes](https://augustschell.com/quotes/)

Open main navigation

Close main navigation

- [Services](https://augustschell.com/services/)
  
  Show submenu for Services 
  
    - [Professional Services Offerings](https://augustschell.com/services-offering/)
- Solutions
  
  Show submenu for Solutions 
  
    - [Security](https://augustschell.com/home-security-solutions/)
    - [Big Data](https://augustschell.com/home-solutions-data/)
- [Resources](https://augustschell.com/resources/)
- [Company](https://augustschell.com/about-us/)
  
  Show submenu for Company 
  
    - [Customers](https://augustschell.com/customers/)
    - [Partners](https://augustschell.com/partners/)
    - [Joint Ventures](https://augustschell.com/home-company-joint-ventures/)
    - [Contracts](https://augustschell.com/contracts-2/)
    - [Where to Find Us](https://augustschell.com/home-company-news/)
    - [About Us](https://augustschell.com/about/)
    - [Contact](https://augustschell.com/contact/)
- [Quotes](https://augustschell.com/quotes/)
- [Careers](https://augustschell.com/careers/)

[Careers](https://augustschell.com/careers/)

 Apr 13, 2017 6:30:57 AM

# Configuring Splunk Access Controls with LDAP

[Eric Nicholson](https://blog.augustschell.com/author/eric-nicholson)

Share: [facebook-f icon](http://www.facebook.com/share.php?u=https://blog.augustschell.com/configuring-splunk-access-controls-ldap) [linkedin-in icon](http://www.linkedin.com/shareArticle?mini=true&url=https://blog.augustschell.com/configuring-splunk-access-controls-ldap) [Twitter icon](https://twitter.com/intent/tweet?url=https://blog.augustschell.com/configuring-splunk-access-controls-ldap) [pinterest-p icon](http://pinterest.com/pin/create/link/?url=https://blog.augustschell.com/configuring-splunk-access-controls-ldap) [envelope icon](mailto:?body=https://blog.augustschell.com/configuring-splunk-access-controls-ldap)

Configuring [Splunk](https://augustschell.com/partners/splunk/) access controls with LDAP can be a challenge to get all the proper settings to successfully connect and then again to obtain the proper groups that have been configured. The use of Splunk LDAP browsing utilities, such as *Linux LDAP search command* and *Windows LDAP browser*, can be helpful in this venture rather than guessing or relying on default settings provided by documentation.

Here we will be giving and example utilizing a free public test LDAP server, [www.zflexldap.com](http://www.zflexldap.com). The credentials provided by zFLEX LDAP credentials are:

**Server:** www.zflexldap*.com *  
**Port: ***389*  
**Bind DN:** *cn=ro\_admin,ou=sysadmins,dc=zflexsoftware,dc=com*  
**Bind Password**: zflexpass

With the settings provided we can begin to configure the LDAP Access Controls by going to:  
 Setting ->  Access controls -> Authentiction method -> LDAP strategies > Add new

![Configuring Splunk Access Controls with LDAP](https://blog.augustschell.com/hs-fs/hubfs/Imported_Blog_Media/splunk-access-controls-ldap.png?width=942&height=122&name=splunk-access-controls-ldap.png) *Figure 1 Access Control Settings*

The first section is configuring the main LDAP connection with the settings provided.

![Configuring Splunk Access Controls with LDAP](https://blog.augustschell.com/hs-fs/hubfs/Imported_Blog_Media/splunk-access-controls-ldap-2.png?width=975&height=557&name=splunk-access-controls-ldap-2.png) *Figure 2 Configure LDAP connection settings*

The second section addresses configuring the [User Settings](https://info.augustschell.com/ia-2-nist-800-53-with-splunk). At this point is when utilizing an LDAP browser tool. There are various tools available for use for Windows and in this example zFLEX provides a Windows base tool zFLEX LDAP Browser. For Linux, there is the lpdapsearch command line tool which can be installed utilizing which we will use.  If the ldapsearch command is not installed, you install it via yum: 

![configuring splunk](https://blog.augustschell.com/hs-fs/hubfs/Imported_Blog_Media/splunk-access-controls-ldap-3.png?width=553&height=42&name=splunk-access-controls-ldap-3.png) *Figure 3 yum installation*

Utilizing an LDAP browser tool can help us determine settings such as **User base DN** and **User name attribute**. These settings may not be apparent from the original configuration settings provided. Running an ldapsearch command as follows will help shed some light:

![splunk access controls](https://blog.augustschell.com/hs-fs/hubfs/Imported_Blog_Media/splunk-access-controls-ldap-4.png?width=1059&height=41&name=splunk-access-controls-ldap-4.png) *Figure 4 ldap search command* 

 

![splunk access controls with ldap](https://blog.augustschell.com/hs-fs/hubfs/Imported_Blog_Media/splunk-access-controls-ldap-5.png?width=600&height=267&name=splunk-access-controls-ldap-5.png)

*Figure 5 ldap search command output*

From here we determine the **User Base DN** for admin from *dn: ou=sysadmins,dc=zflexsoftware,dc=com* and the **User Name** attribute will be *uid.* 

![configuring splunk access controls](https://blog.augustschell.com/hs-fs/hubfs/Imported_Blog_Media/splunk-access-controls-ldap-6.png?width=975&height=510&name=splunk-access-controls-ldap-6.png) *Figure 6 LDAP User Settings*

The Group settings follows and we can continue to use this information to complete the configuration: 

![splunk ldap search access controls](https://blog.augustschell.com/hs-fs/hubfs/Imported_Blog_Media/splunk-access-controls-ldap-7.png?width=975&height=412&name=splunk-access-controls-ldap-7.png)  *Figure 7 LDAP Group Settings*

At this point we should be able to save our configuration. This process will validate the LDAP connection and login. If any errors occur, review the settings with the ldapsearch output.

The next objective is to map LDAP groups to Splunk roles. Groups will need to be created within LDAP that contain user’s that pertain to that group.  For example, create a Security Admins group for security engineers and a group for Network Admins for network engineers.

Within the LDAP Strategies select **Map Groups** under **Actions** on the right side.

 

![splunk access controls ldap](https://blog.augustschell.com/hs-fs/hubfs/Imported_Blog_Media/splunk-access-controls-ldap-8.png?width=1104&height=41&name=splunk-access-controls-ldap-8.png) *Figure 8 LDAP Strategies*

 

Here we can see the groups that are available for mapping to Splunk roles.

 

![splunk ldap](https://blog.augustschell.com/hs-fs/hubfs/Imported_Blog_Media/splunk-access-controls-ldap-9.png?width=1026&height=87&name=splunk-access-controls-ldap-9.png) *Figure 9 LDAP Available Groups*

 Select the group that you wish to map, here we will use an example of mapping ServerAdmin to the Splunk Admin Role.

We select the ServerAdmin Group and then select the Admin role in the Left column to add it to the Right Column. In the figure below you can see the LDAP Users contained within that group. 

![configuring splunk](https://blog.augustschell.com/hs-fs/hubfs/Imported_Blog_Media/splunk-access-controls-ldap-10.png?width=975&height=416&name=splunk-access-controls-ldap-10.png) *Figure 10 LDAP Assigning Roles to Groups*

 After saving you will see the roles assigned to that group:

![splunk access controls](https://blog.augustschell.com/hs-fs/hubfs/Imported_Blog_Media/splunk-access-controls-ldap-11.png?width=1065&height=39&name=splunk-access-controls-ldap-11.png) *Figure 11 LDAP Assigned Roles*

 

---

#### ![How to create a splunk dashboard](https://blog.augustschell.com/hs-fs/hubfs/Screen%20Shot%202018-05-03%20at%2012.26.14%20PM.png?width=300&height=152&name=Screen%20Shot%202018-05-03%20at%2012.26.14%20PM.png)Want to learn more about how to use Splunk? Check out the videos our engineers put together as educational resources!

[![Watch Now](https://no-cache.hubspot.com/cta/default/4039791/b2fa7997-8a2a-4b62-a8b8-888114391e98.png)](https://cta-redirect.hubspot.com/cta/redirect/4039791/b2fa7997-8a2a-4b62-a8b8-888114391e98) 

 

[Splunk](https://blog.augustschell.com/tag/splunk)

## Related posts

[![demos-proofs-concept](https://blog.augustschell.com/hs-fs/hubfs/demos-proofs-concept.jpg?height=200&name=demos-proofs-concept.jpg)](https://blog.augustschell.com/always-architect-demos-proofs-of-concept-for-production-use)

[Computer Engineer](https://blog.augustschell.com/tag/computer-engineer)

## [Always Architect Demos & Proofs of Concept for Production Use](https://blog.augustschell.com/always-architect-demos-proofs-of-concept-for-production-use)

[Warren Myers](https://blog.augustschell.com/author/warren-myers) 

 Feb 8, 2018 8:18:00 AM

One thing I learned very, very early in my professional career is that there is no such thing as a...

[Read more](https://blog.augustschell.com/always-architect-demos-proofs-of-concept-for-production-use)

[![containers](https://blog.augustschell.com/hs-fs/hubfs/containers.jpg?height=200&name=containers.jpg)](https://blog.augustschell.com/the-evolution-of-virtualization-servers-and-containers)

[Containers](https://blog.augustschell.com/tag/containers), [serverless technology](https://blog.augustschell.com/tag/serverless-technology), [virtualization](https://blog.augustschell.com/tag/virtualization)

## [The Evolution of Virtualization, Servers and Containers](https://blog.augustschell.com/the-evolution-of-virtualization-servers-and-containers)

[Ron Flax](https://blog.augustschell.com/author/ron-flax) 

 May 24, 2018 7:43:00 AM

How Virtualization Led to Container and Serverless Technology

[Read more](https://blog.augustschell.com/the-evolution-of-virtualization-servers-and-containers)

[![containers](https://blog.augustschell.com/hs-fs/hubfs/containers.png?height=200&name=containers.png)](https://blog.augustschell.com/tame-excitement-containers-introducing-red-hat-openshift-container-platform)

[OpenShift](https://blog.augustschell.com/tag/openshift), [Red Hat](https://blog.augustschell.com/tag/red-hat), [Containers](https://blog.augustschell.com/tag/containers)

## [Tame the Excitement of Containers: Introducing Red Hat OpenShift Container Platform](https://blog.augustschell.com/tame-excitement-containers-introducing-red-hat-openshift-container-platform)

[Admin](https://blog.augustschell.com/author/admin) 

 Dec 7, 2017 5:00:37 AM

Automating the Process of Container-Based Application Development Containers have brought a lot of...

[Read more](https://blog.augustschell.com/tame-excitement-containers-introducing-red-hat-openshift-container-platform)

---

Talk to an Expert `Today.`

*[![Contact Us](https://no-cache.hubspot.com/cta/default/4039791/interactive-182720921209.png)](https://blog.augustschell.com/hs/cta/wi/redirect?encryptedPayload=AVxigLLUgWqz%2BoAQ3%2F4%2FO8dSgmhSDa8vP2wVE4Ut%2F%2BYVW04HCSuTi8%2Btc7U8pQD3L4QoCevh27yLYTG8z0e8MRHmTnq9WPu7pQHXjGcHanq37iXz1EBJYKowfqP6AVLrkgx14rPH9ql4JUhCpXzV%2Fpi0YiTpSDpk7Fbu1o2FStPgPvYNajVtig%3D%3D&webInteractiveContentId=182720921209&portalId=4039791)*

| Quick Links [Request Quote](https://augustschell.com/quotes/) [Careers](https://augustschell.com/careers/) [Contracts](https://augustschell.com/contracts/) | 1700 Rockville Pike, Suite 405, Rockville MD 20852 (301) 838-9470 [![Screenshot 2024-11-12 at 10.57.50 AM](https://blog.augustschell.com/hs-fs/hubfs/Screenshot%202024-11-12%20at%2010.57.50%20AM.png?width=110&height=22&name=Screenshot%202024-11-12%20at%2010.57.50%20AM.png)](https://www.linkedin.com/company/august-schell-enterprises) |
| --- | --- |

 

| **August Schell** | [Privacy Policy](https://augustschell.com/privacy-policy/) · [Contact Us](https://augustschell.com/contact/) | All rights reserved |
| --- | --- | --- |

 