Sure... When you do group mapping, map them to groups that don't have the domain admins in them. I have a separate OU=Groups that has "Splunk Users, Splunk Admins, Splunk Power Users" as group names, and specific users…
I want to give LDAP access to my splunk servcie but I don't want the LDAP users to have admin capabilitys in Splunk. Can I keep the domain admins out of Splunk if I have LDAP authentication???
Helow Jonathan,
Glad to have another Splunker. I've been useing Splunk for 2 years and am hooked. I leared how to spell splunk and | transaction too. you'll learn that one soon.
Go over to Splunk…
Holy Batskins Ninja, zzzzzwap zgruppp kapow a hidden stash, how great is that!!!!
The team that found them must have special bat senses and highly tooned Splunking skills
I like to wear Extra Lovable…
Feb 7
Learning, learning, learning . . . Our Splunk "expert" is gone, and the non-programmer gets to learn the task! How do you spell SPLUNK?
Is there any way to create event aggregation in splunk ?
what happened is I got license violations do to Windows security event
log that repeated itself over 600,000 times in 2 hours
is there a way that I can "teach" splunk to alert when such a think
happen and ignore or drop the excessive event
splunk version is 4.0.10 .and for now I have an alert on license
violation , after the alert I searched for the 'Top
five sourcetypes (by total KB indexed) in the last 24 hours' (splunkninja.com/profiles/blogs/getting-more-intelligence-on) and found the
problematic event , but I only did this after the license violation
occurred