How the Splunk platform works with multiple LDAP servers for authentication

The Splunk platform can search against multiple LDAP servers when it authenticates users. To configure multiple LDAP servers, you set up multiple LDAP "strategies," one for each LDAP server.

After you create LDAP strategies, you can specify the order in which you want the Splunk platform to query the strategies when searching for LDAP users. If you do not specify a search order, the Splunk platform assigns a default "connection order" based on the order in which you created the strategies.

For more about the steps to configure LDAP strategies, see Configure LDAP with Splunk Web. If you use Splunk Web, you can also see Configure LDAP with configuration files.

How connection order works during a search