Splunk Search

How to search for users that no longer exist in LDAP so I can remove their user directories from Splunk?

rmorlen
Splunk Employee
Splunk Employee

We use LDAP for user authentication. We have many, many users. Anyone have a search or script where I can find users that no longer exist in LDAP so that I can remove their user directories from Splunk?

Another way to address the issue is how can I go through the list of user directories and validate that the user for that directory still exists? (Linux)

Tags (4)
0 Karma

MuS
Legend

Hi rmorlen,

You can try the solution provided here http://answers.splunk.com/answers/107574/track-users-logging-in-via-sso.html or use the LDAP add on http://apps.splunk.com/app/1852 which enables Splunk to perform nativ LDAP queries and browser for the user on your LDAP server.

Hope that helps ...

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...