Splunk Search

How to search for users that no longer exist in LDAP so I can remove their user directories from Splunk?

rmorlen
Splunk Employee
Splunk Employee

We use LDAP for user authentication. We have many, many users. Anyone have a search or script where I can find users that no longer exist in LDAP so that I can remove their user directories from Splunk?

Another way to address the issue is how can I go through the list of user directories and validate that the user for that directory still exists? (Linux)

Tags (4)
0 Karma

MuS
Legend

Hi rmorlen,

You can try the solution provided here http://answers.splunk.com/answers/107574/track-users-logging-in-via-sso.html or use the LDAP add on http://apps.splunk.com/app/1852 which enables Splunk to perform nativ LDAP queries and browser for the user on your LDAP server.

Hope that helps ...

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...