Multiple group_search.base_dn for one LDAP/AD

We have two spots for groups to reside inside of AD, which are not children of the same folders (but in the same domain). I am looking for a way to have ES search them both to get the group membership, while not traversing the other the entire domain. I am looking for something like this, and wanted to see if anyone had suggestions or cautions on adding multiple base_dn for group searches.


We are on AD realm currently, and will be moving to LDAP in the near future. Anybody else go through this? Is adding another realm the solution (though it seems overkill as the users are not different)?

As an additional ask:

Is it possible to filter specific words out of the groups returned? Specifically looking to drop distribution groups from the results.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.