Splunk Search

How to search for users that no longer exist in LDAP so I can remove their user directories from Splunk?

rmorlen
Splunk Employee
Splunk Employee

We use LDAP for user authentication. We have many, many users. Anyone have a search or script where I can find users that no longer exist in LDAP so that I can remove their user directories from Splunk?

Another way to address the issue is how can I go through the list of user directories and validate that the user for that directory still exists? (Linux)

Tags (4)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi rmorlen,

You can try the solution provided here http://answers.splunk.com/answers/107574/track-users-logging-in-via-sso.html or use the LDAP add on http://apps.splunk.com/app/1852 which enables Splunk to perform nativ LDAP queries and browser for the user on your LDAP server.

Hope that helps ...

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...