<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic splunk ldap errors troubleshoot in Security</title>
    <link>https://community.splunk.com/t5/Security/splunk-ldap-errors-troubleshoot/m-p/478291#M11044</link>
    <description>&lt;P&gt;Hello&lt;BR /&gt;
I got complains that a users cannot login in splunk(Ldap setup) with error "Login failed" and if they wait 10 minutes , then is successful.&lt;BR /&gt;
I checked the logs splunkd and there are Timeout messages once in a while as well as a lot of "Operation Error" but not else more precise.&lt;BR /&gt;
If I go in UI -&amp;gt; reload authentication strategy - &amp;gt; No error and everything is success, as well as I can see users under different mapped groups.&lt;/P&gt;

&lt;P&gt;I have tried some different troubleshoot methods but nothing works.&lt;BR /&gt;
1. Tried to run from unix terminal :&lt;BR /&gt;
ldapsearch -x –h myLdapserver –p myLdapserverport –D "bind_dn" -w "bind_passwd" -b "user_basedn" "userNameAttribute=*"&lt;BR /&gt;
-&amp;gt; ldap_result: Can't contact LDAP server (-1)&lt;BR /&gt;
so I am not sure is the command correct and is it correct that I run it not like this ./splunk ldapsearch...?&lt;BR /&gt;
I must be that the command is wrong because if there was somthing wrong with the ldap server then I guess all login attempts was going to fail all of the time which is not the case. &lt;BR /&gt;
How can I troubleshoot if the problem is comming due to a long wait(there are two timeout settings in authentication.conf ) How to check if the problem is due to some of these are too low?&lt;/P&gt;

&lt;P&gt;I tried also to run&lt;BR /&gt;
| ldapsearch in splunk UI - result: after 2-3 minütes waiting seeming as it runs:&lt;BR /&gt;
External search command 'ldapsearch' returned error code 1. Script output = "error_message=AttributeError at "/pack/splunk/etc/apps/SA-ldapsearch/bin/packages/app/&lt;EM&gt;init&lt;/EM&gt;.py", line 325 : 'LDAPSocketOpenError' object has no attribute 'replace' ".&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 04:20:17 GMT</pubDate>
    <dc:creator>net1993</dc:creator>
    <dc:date>2020-09-30T04:20:17Z</dc:date>
    <item>
      <title>splunk ldap errors troubleshoot</title>
      <link>https://community.splunk.com/t5/Security/splunk-ldap-errors-troubleshoot/m-p/478291#M11044</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;
I got complains that a users cannot login in splunk(Ldap setup) with error "Login failed" and if they wait 10 minutes , then is successful.&lt;BR /&gt;
I checked the logs splunkd and there are Timeout messages once in a while as well as a lot of "Operation Error" but not else more precise.&lt;BR /&gt;
If I go in UI -&amp;gt; reload authentication strategy - &amp;gt; No error and everything is success, as well as I can see users under different mapped groups.&lt;/P&gt;

&lt;P&gt;I have tried some different troubleshoot methods but nothing works.&lt;BR /&gt;
1. Tried to run from unix terminal :&lt;BR /&gt;
ldapsearch -x –h myLdapserver –p myLdapserverport –D "bind_dn" -w "bind_passwd" -b "user_basedn" "userNameAttribute=*"&lt;BR /&gt;
-&amp;gt; ldap_result: Can't contact LDAP server (-1)&lt;BR /&gt;
so I am not sure is the command correct and is it correct that I run it not like this ./splunk ldapsearch...?&lt;BR /&gt;
I must be that the command is wrong because if there was somthing wrong with the ldap server then I guess all login attempts was going to fail all of the time which is not the case. &lt;BR /&gt;
How can I troubleshoot if the problem is comming due to a long wait(there are two timeout settings in authentication.conf ) How to check if the problem is due to some of these are too low?&lt;/P&gt;

&lt;P&gt;I tried also to run&lt;BR /&gt;
| ldapsearch in splunk UI - result: after 2-3 minütes waiting seeming as it runs:&lt;BR /&gt;
External search command 'ldapsearch' returned error code 1. Script output = "error_message=AttributeError at "/pack/splunk/etc/apps/SA-ldapsearch/bin/packages/app/&lt;EM&gt;init&lt;/EM&gt;.py", line 325 : 'LDAPSocketOpenError' object has no attribute 'replace' ".&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:20:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/splunk-ldap-errors-troubleshoot/m-p/478291#M11044</guid>
      <dc:creator>net1993</dc:creator>
      <dc:date>2020-09-30T04:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: splunk ldap errors troubleshoot</title>
      <link>https://community.splunk.com/t5/Security/splunk-ldap-errors-troubleshoot/m-p/478292#M11045</link>
      <description>&lt;P&gt;Splunk LDAP search is, by default, limited to the first 1000 searches. If a user exists beyond that, it will fail.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2020 00:22:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/splunk-ldap-errors-troubleshoot/m-p/478292#M11045</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2020-03-17T00:22:49Z</dc:date>
    </item>
  </channel>
</rss>

