<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I improve ldapsearch performance in Security</title>
    <link>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246737#M6839</link>
    <description>&lt;P&gt;Hi MuS, Thanks for your response. I'm using the SA-ldapsearch. I hope you can help resolve this performance problem.&lt;BR /&gt;
Just to check if Splunk was the problem or NOT. I installed the Centos ldapsearch client and executed the same Active Directory search I've been trying through Splunk, and the AD results return in seconds.&lt;BR /&gt;
So it seems to me the problem is with Splunk and not Active Directly or my system.&lt;/P&gt;</description>
    <pubDate>Mon, 30 Nov 2015 06:37:00 GMT</pubDate>
    <dc:creator>napomokoetle</dc:creator>
    <dc:date>2015-11-30T06:37:00Z</dc:date>
    <item>
      <title>How do I improve ldapsearch performance</title>
      <link>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246733#M6835</link>
      <description>&lt;P&gt;My environment:&lt;/P&gt;

&lt;P&gt;Splunk Supporting Add-on for Active Directory 2.1.1&lt;BR /&gt;
Splunk Enterprise 6.3.1&lt;BR /&gt;
Running on Linux Centos 6.5&lt;/P&gt;

&lt;P&gt;When I execute any LDAP search I have to wait for at least 5 minutes before I see results back! This is extremely slow. What can I do to troubleshoot this performance problem and improve the performance? &lt;/P&gt;

&lt;P&gt;Kind regards,&lt;BR /&gt;
J. Napo Mokoetle&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2015 11:54:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246733#M6835</guid>
      <dc:creator>napomokoetle</dc:creator>
      <dc:date>2015-11-26T11:54:50Z</dc:date>
    </item>
    <item>
      <title>Re: How do I improve ldapsearch performance</title>
      <link>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246734#M6836</link>
      <description>&lt;P&gt;This has been broken for as long as it has existed.&lt;/P&gt;

&lt;P&gt;I check with an os based ldapsearch and it instantly returns. As soon as you try to do it in the addon it's pretty much useless. We have a massive number of use cases for this and we have to resort to using external tools &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2015 13:36:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246734#M6836</guid>
      <dc:creator>Lucas_K</dc:creator>
      <dc:date>2015-11-26T13:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: How do I improve ldapsearch performance</title>
      <link>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246735#M6837</link>
      <description>&lt;P&gt;Frustrating! Let's hope someone from Splunk or otherwise will hear our cry and help us out of our specific ldapsearch related pain Lucas K &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; . &lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2015 15:43:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246735#M6837</guid>
      <dc:creator>napomokoetle</dc:creator>
      <dc:date>2015-11-26T15:43:52Z</dc:date>
    </item>
    <item>
      <title>Re: How do I improve ldapsearch performance</title>
      <link>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246736#M6838</link>
      <description>&lt;P&gt;Hi napomokoetle,&lt;/P&gt;

&lt;P&gt;just a quick question: do you use the LDPA Add-on or the SA-ldapsearch? I'm asking because you tagged the question with &lt;CODE&gt;Add-on for LDAP&lt;/CODE&gt; which does not provide a &lt;CODE&gt;ldapsearch&lt;/CODE&gt; command and listed the &lt;CODE&gt;Add-on for Active Directory&lt;/CODE&gt; as well...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Sun, 29 Nov 2015 19:32:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246736#M6838</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2015-11-29T19:32:28Z</dc:date>
    </item>
    <item>
      <title>Re: How do I improve ldapsearch performance</title>
      <link>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246737#M6839</link>
      <description>&lt;P&gt;Hi MuS, Thanks for your response. I'm using the SA-ldapsearch. I hope you can help resolve this performance problem.&lt;BR /&gt;
Just to check if Splunk was the problem or NOT. I installed the Centos ldapsearch client and executed the same Active Directory search I've been trying through Splunk, and the AD results return in seconds.&lt;BR /&gt;
So it seems to me the problem is with Splunk and not Active Directly or my system.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2015 06:37:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246737#M6839</guid>
      <dc:creator>napomokoetle</dc:creator>
      <dc:date>2015-11-30T06:37:00Z</dc:date>
    </item>
    <item>
      <title>Re: How do I improve ldapsearch performance</title>
      <link>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246738#M6840</link>
      <description>&lt;P&gt;I am dealing with a large domain, and an LDAPsearch takes over 8 hours to complete - but it usually times out.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2016 18:35:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246738#M6840</guid>
      <dc:creator>gwalford</dc:creator>
      <dc:date>2016-02-11T18:35:03Z</dc:date>
    </item>
    <item>
      <title>Re: How do I improve ldapsearch performance</title>
      <link>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246739#M6841</link>
      <description>&lt;P&gt;I suppose Splunk also has no clue on fixing this one or helping us get it right.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2016 20:34:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246739#M6841</guid>
      <dc:creator>napomokoetle</dc:creator>
      <dc:date>2016-02-11T20:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: How do I improve ldapsearch performance</title>
      <link>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246740#M6842</link>
      <description>&lt;P&gt;Hi napomokoetle,&lt;/P&gt;

&lt;P&gt;did you open a support case? &lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2016 20:39:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246740#M6842</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2016-02-11T20:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: How do I improve ldapsearch performance</title>
      <link>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246741#M6843</link>
      <description>&lt;P&gt;Hi Mus,&lt;/P&gt;

&lt;P&gt;I have had the problem for a very long time and don't recall  opening a trouble ticket. But there are many others who have had the same problem and opened tickets but I believe they never had the problem solved.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2016 03:27:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246741#M6843</guid>
      <dc:creator>napomokoetle</dc:creator>
      <dc:date>2016-02-12T03:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: How do I improve ldapsearch performance</title>
      <link>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246742#M6844</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;Have you tried this : &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;To improve performance on queries against ADs with large numbers of users, select only the query attributes you need to complete your analysis. For example, if you need just two attributes, distinguishedName and sAMAccountName, say so. Use this command:

| ldapsearch search="(objectClass=user)" attrs="distinguishedName,sAMAccountName"

instead of:

| ldapsearch search="(objectClass=user)"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It comes from the documentation :&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/SA-LdapSearch/latest/User/UseSA-ldapsearchtotroubleshootproblems"&gt;http://docs.splunk.com/Documentation/SA-LdapSearch/latest/User/UseSA-ldapsearchtotroubleshootproblems&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I tried and it significantly improved our performance.&lt;/P&gt;

&lt;P&gt;Hope it will help !&lt;BR /&gt;
Romain.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2016 19:52:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246742#M6844</guid>
      <dc:creator>rtestu_splunk</dc:creator>
      <dc:date>2016-03-16T19:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: How do I improve ldapsearch performance</title>
      <link>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246743#M6845</link>
      <description>&lt;P&gt;Hi rtestu,&lt;/P&gt;

&lt;P&gt;Thanks for the response.&lt;BR /&gt;
I do use very specific searches. But the result is still very sluggish response. Still have to weight at last 5 minutes for any results to show up!&lt;BR /&gt;
Here's an example query I execute:&lt;/P&gt;

&lt;P&gt;search="(&amp;amp;(objectclass=user)(!(objectClass=computer))(accountExpires=9223372036854775807))"|sort sAMAccountName|table sAMAccountName,cn,userPrincipalName,userAccountControl&lt;/P&gt;

&lt;P&gt;Could someone perhaps suggest ways to trace the situation to get to where the bottleneck could be?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2016 12:45:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246743#M6845</guid>
      <dc:creator>napomokoetle</dc:creator>
      <dc:date>2016-03-17T12:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: How do I improve ldapsearch performance</title>
      <link>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246744#M6846</link>
      <description>&lt;P&gt;And did you try what I mentioned ?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| ldapsearch search="(&amp;amp;(objectclass=user)(!(objectClass=computer))(accountExpires=9223372036854775807))"
attrs="sAMAccountName,cn,userPrincipalName,userAccountControl"
| sort sAMAccountName
| table sAMAccountName,cn,userPrincipalName,userAccountControl
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It could significantly improve the performance if you have to retrieve lots of data from the LDAP. In your case, I am not sure it will improve a lot since you seem to retrieve a few accounts ...&lt;/P&gt;

&lt;P&gt;Romain.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2016 13:04:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246744#M6846</guid>
      <dc:creator>rtestu_splunk</dc:creator>
      <dc:date>2016-03-17T13:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: How do I improve ldapsearch performance</title>
      <link>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246745#M6847</link>
      <description>&lt;P&gt;Hi retestu,&lt;/P&gt;

&lt;P&gt;Yes I als tried limiting the attributes as you suggested but it's not helping.&lt;/P&gt;

&lt;P&gt;The odd thing is when I perform the search from the command line on the same search head as show below, the results return immediately. &lt;/P&gt;

&lt;P&gt;[root@JHBTNXSPL111 ~]# ldapsearch -x -b "DC=inter,DC=Kransnetwork,DC=Net" -D "CN=SRV-TCC-Splunk LDAP,OU=Service Accounts,OU=Groups,OU=TCC,DC=inter,DC=Kransnetwork,DC=net" -w "I3m5TFfB\$uh2%ze" -h 10.10.227.150 -p 389 -A '(&amp;amp;(objectclass=user)(!(objectClass=computer))(accountExpires=9223372036854775807))'&lt;/P&gt;

&lt;P&gt;Also, the Splunk solution uses LDAP integration to authenticate users and it works just fine when users use the AD credentials to log in. &lt;/P&gt;

&lt;P&gt;So it really seems to me like the problem is with the "Splunk Supporting Add-on for Active Directory". &lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2016 13:42:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246745#M6847</guid>
      <dc:creator>napomokoetle</dc:creator>
      <dc:date>2016-03-17T13:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: How do I improve ldapsearch performance</title>
      <link>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246746#M6848</link>
      <description>&lt;P&gt;There is no doubt the root cause is the addon.&lt;/P&gt;

&lt;P&gt;A local os based ldapsearch takes milliseconds. The addon based one takes minutes.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2016 21:58:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246746#M6848</guid>
      <dc:creator>Lucas_K</dc:creator>
      <dc:date>2016-03-17T21:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: How do I improve ldapsearch performance</title>
      <link>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246747#M6849</link>
      <description>&lt;P&gt;I opened a ticket, it seems that there is a bug in SA-LDAPsearch that is being addressed.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2016 22:39:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246747#M6849</guid>
      <dc:creator>gwalford</dc:creator>
      <dc:date>2016-03-17T22:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: How do I improve ldapsearch performance</title>
      <link>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246748#M6850</link>
      <description>&lt;P&gt;I agree 100%! There is something NOT optimal with that "Splunk Supporting Add-on for Active Directory" that makes it not perform as expected.&lt;/P&gt;

&lt;P&gt;I've seen many other posts from folks experiencing the same problem. The app serves a very useful function, but in its current state it's unusable.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2016 18:30:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246748#M6850</guid>
      <dc:creator>napomokoetle</dc:creator>
      <dc:date>2016-03-18T18:30:25Z</dc:date>
    </item>
    <item>
      <title>Re: How do I improve ldapsearch performance</title>
      <link>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246749#M6851</link>
      <description>&lt;P&gt;Thank you gwalford! I hope this issue can be finally be resolved. Much appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2016 18:31:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246749#M6851</guid>
      <dc:creator>napomokoetle</dc:creator>
      <dc:date>2016-03-18T18:31:52Z</dc:date>
    </item>
    <item>
      <title>Re: How do I improve ldapsearch performance</title>
      <link>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246750#M6852</link>
      <description>&lt;P&gt;I strongly recommend you open a ticket on this issue as well.&lt;/P&gt;

&lt;P&gt;The more customers that open tickets, the higher of a priority this becomes on the DEV side, and the more quickly you will get this issue addressed.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2016 21:14:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246750#M6852</guid>
      <dc:creator>gwalford</dc:creator>
      <dc:date>2016-03-18T21:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: How do I improve ldapsearch performance</title>
      <link>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246751#M6853</link>
      <description>&lt;P&gt;I'll do so.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Mar 2016 12:34:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246751#M6853</guid>
      <dc:creator>napomokoetle</dc:creator>
      <dc:date>2016-03-19T12:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: How do I improve ldapsearch performance</title>
      <link>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246752#M6854</link>
      <description>&lt;P&gt;This issue makes me a very sad panda. &lt;/P&gt;

&lt;P&gt;I've had a case open with support since 12/2015 for this issue. They acknowledged that it is an issue they are working on, but still no fix. The problem started with v2 of the add-on. If you go back to the v1 version, which is Java based:-(, the performance is on par with normal LDAP queries. The downside, beyond Java, of downgrading to v1 is that there are lots of features missing. Namely Non-ASCII character support and ability to specify a BaseDN. Going back to v1 broke apps that we use and have created so we are back on slow v2. We try to use scheduled reports as much as possible to hide the slow searching, but that is not ideal, especially for developing searches.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2016 01:56:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-I-improve-ldapsearch-performance/m-p/246752#M6854</guid>
      <dc:creator>the0duke0</dc:creator>
      <dc:date>2016-06-24T01:56:27Z</dc:date>
    </item>
  </channel>
</rss>

