<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk LDAP integration support LDAP Extended Controls? in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-LDAP-integration-support-LDAP-Extended-Controls/m-p/147979#M4532</link>
    <description>&lt;P&gt;Does Splunk LDAP intergration support LDAP Extended Controls?  In particular Matching rule OID 1.2.840.113556.1.4.1941 which is a special "extended match operator that walks the chain of ancestry in objects all the way to the root until it finds a match. &lt;/P&gt;

&lt;P&gt;I've tried implement this in my ldap strategy, but Splunk pukes; however, if I pass the same LDAP query listed in the AuthenticationManagerLDAP logging channel using Apache Directory Studio it works fine.&lt;/P&gt;

&lt;P&gt;Thanks in advanced,&lt;/P&gt;

&lt;P&gt;Additiona Links:&lt;BR /&gt;
&lt;A href="http://msdn.microsoft.com/en-us/library/aa746475(v=vs.85).aspx"&gt;Search Filter Syntax&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://msdn.microsoft.com/en-us/library/cc223320.aspx"&gt;3.1.1.3.4.1 LDAP Extended Control&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://www.msresource.net/knowledge_base/articles/info:_what_are_active_directory_recursive_queries.html"&gt;Active Directory Recursive Queries&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Apr 2014 19:46:12 GMT</pubDate>
    <dc:creator>bmacias84</dc:creator>
    <dc:date>2014-04-30T19:46:12Z</dc:date>
    <item>
      <title>Splunk LDAP integration support LDAP Extended Controls?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-LDAP-integration-support-LDAP-Extended-Controls/m-p/147979#M4532</link>
      <description>&lt;P&gt;Does Splunk LDAP intergration support LDAP Extended Controls?  In particular Matching rule OID 1.2.840.113556.1.4.1941 which is a special "extended match operator that walks the chain of ancestry in objects all the way to the root until it finds a match. &lt;/P&gt;

&lt;P&gt;I've tried implement this in my ldap strategy, but Splunk pukes; however, if I pass the same LDAP query listed in the AuthenticationManagerLDAP logging channel using Apache Directory Studio it works fine.&lt;/P&gt;

&lt;P&gt;Thanks in advanced,&lt;/P&gt;

&lt;P&gt;Additiona Links:&lt;BR /&gt;
&lt;A href="http://msdn.microsoft.com/en-us/library/aa746475(v=vs.85).aspx"&gt;Search Filter Syntax&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://msdn.microsoft.com/en-us/library/cc223320.aspx"&gt;3.1.1.3.4.1 LDAP Extended Control&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://www.msresource.net/knowledge_base/articles/info:_what_are_active_directory_recursive_queries.html"&gt;Active Directory Recursive Queries&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2014 19:46:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-LDAP-integration-support-LDAP-Extended-Controls/m-p/147979#M4532</guid>
      <dc:creator>bmacias84</dc:creator>
      <dc:date>2014-04-30T19:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk LDAP integration support LDAP Extended Controls?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-LDAP-integration-support-LDAP-Extended-Controls/m-p/147980#M4533</link>
      <description>&lt;P&gt;We have done this, and it does work.&lt;/P&gt;

&lt;P&gt;Here is an example of what we did.&lt;/P&gt;

&lt;P&gt;(&amp;amp;(objectClass=user)(memberOf:1.2.840.113556.1.4.1941:=cn=Splunk Access,ou=Groups,dc=contoso,dc=com))&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 19:50:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-LDAP-integration-support-LDAP-Extended-Controls/m-p/147980#M4533</guid>
      <dc:creator>thorwright</dc:creator>
      <dc:date>2014-09-19T19:50:21Z</dc:date>
    </item>
  </channel>
</rss>

