If someone wants to integrate Splunk with Tivoli Access Manager WebSEAL for authentication management, which apparently uses IBM LDAP 3, does anyone know if Splunk can do this?
Unfortunately Splunk does not support the iv _ groups HTTP header, only iv _ user - so you still will need to let Splunk use LDAP or some scripted authentication solution.
If only Splunk did support the iv _ group HTTP header, putting Splunk behind WebSeal would really be a non-brainer.
Yes, Splunk can do this.
Please Note: You will need to set a non-empty root_endpoint path in splunk (probably in web.conf or server.conf, I think) and set the Splunk app up as a "transparent junction" with the same path/endpoint in TAM (i.e. some TAM-related thing that your administrator will have to do) as a regular junction won't work correctly, I believe.