Splunk Search

Search Head and LDAP

joberget
Path Finder

Does Search Head servers have anything more in common than which Indexer they are connected to? If I want two Search Heads to do LDAP authentication against the same AD I need to set it up the same way on both of the Search Heads? Or do they sync configuration in some way?

Is it also possible to set up two search heads authenticate against two different ADs but share the same Indexer servers? I guess this will cause some role and permission troubles when there are two different ADs. This would be great if customers want their own Search Head and authenticate against their own AD.

0 Karma

David
Splunk Employee
Splunk Employee

With the current setup, search heads are totally independent. I believe it's in the roadmap to do more of a clustering setup, but for now, you just need to mirror your authentication.conf (and authorization.conf as appropriate). I'm not sure when the "cluster-esque" setup will arrive, though.

And yes, I don't think there should be any issues setting up different search heads to use totally different authentication schemes. It's probably best to test this out before investing too much time / money though 😉

gkanapathy
Splunk Employee
Splunk Employee

It's fine to use totally different auth on different search heads. The indexers do not know anything about authentication, as it is entirely managed by and delegated to the search head, so every search head can run independently. (From 4.2 on, they can be configured in a pool, but they don't have to be.)

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...