<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to install SA_LDAPSearch on Splunk Cloud in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-SA-LDAPSearch-on-Splunk-Cloud/m-p/592868#M76552</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/41609"&gt;@b_chris21&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;no, the Search Head Role is only for Splunk queries, LDAP Search is a connector to extract data from AD and take in Splunk.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 07 Apr 2022 10:47:35 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-04-07T10:47:35Z</dc:date>
    <item>
      <title>How to install SA_LDAPSearch on Splunk Cloud</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-SA-LDAPSearch-on-Splunk-Cloud/m-p/429752#M52631</link>
      <description>&lt;P&gt;Hi at all,&lt;BR /&gt;
I have to install the SA-LDAPSearch App on Splunk Cloud to query a Domain Controller.&lt;BR /&gt;
I have in my infrastructure two Heavy Forwarders that concentrate logs from my target servers and send them to Splunk Cloud.&lt;BR /&gt;
My problem is: SA-LDAPSearch App is usually installed on a Search Head, but To do this, in Splunk Cloud, I should open a port from Splunk Cloud to my Domain Controllers and I'd like to avoid this.&lt;BR /&gt;
Is it possible to install it on my Heavy Forwarder or to use a different approach?&lt;/P&gt;

&lt;P&gt;Thank you in advance.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2018 15:44:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-SA-LDAPSearch-on-Splunk-Cloud/m-p/429752#M52631</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2018-07-09T15:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to install SA_LDAPSearch on Splunk Cloud</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-SA-LDAPSearch-on-Splunk-Cloud/m-p/429753#M52632</link>
      <description>&lt;P&gt;As an alternative, you can utilize the MS Windows AD Objects app &lt;A href="https://splunkbase.splunk.com/app/3177/"&gt;https://splunkbase.splunk.com/app/3177/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;"This application also provides an efficient, alternative, option for looking up AD Object attributes instead of using the Support Add-On for Active Directory (ie remote LDAP Queries). Since the the Splunk for Windows Infrastructure and Splunk for Microsoft Exchange applications require the SA LDAPSearch add-on by default, the MS Windows AD Objects application provides the needed dashboard files to replace the ones provided within these applications."&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2018 17:58:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-SA-LDAPSearch-on-Splunk-Cloud/m-p/429753#M52632</guid>
      <dc:creator>kmorris_splunk</dc:creator>
      <dc:date>2018-07-09T17:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to install SA_LDAPSearch on Splunk Cloud</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-SA-LDAPSearch-on-Splunk-Cloud/m-p/429754#M52633</link>
      <description>&lt;P&gt;Thank you  kmorris,&lt;BR /&gt;
this helps me to have LDAP information in Splunk Cloud.&lt;BR /&gt;
I'd like to understand why the App creators used lookups and eventtypes different than SA-LDAPSearch App, so I have to customize this app to adapt it to Splunk App for Windows Infrastructure !&lt;BR /&gt;
Anyway.&lt;BR /&gt;
Thank you again.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 28 Jul 2018 09:21:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-SA-LDAPSearch-on-Splunk-Cloud/m-p/429754#M52633</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2018-07-28T09:21:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to install SA_LDAPSearch on Splunk Cloud</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-SA-LDAPSearch-on-Splunk-Cloud/m-p/592866#M76551</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have SA-LDAPsearch installed on my Heavy Forwarder. It then forwards all data to my Cloud Instance with Enterprise Security.&lt;/P&gt;&lt;P&gt;Will this work in order to get my assets and identities populated?&lt;/P&gt;&lt;P&gt;In Docs (&lt;A href="https://docs.splunk.com/Documentation/SA-LdapSearch/3.0.4/User/DeploytheSplunkSupportingAdd-onforActiveDirectory" target="_blank"&gt;https://docs.splunk.com/Documentation/SA-LdapSearch/3.0.4/User/DeploytheSplunkSupportingAdd-onforActiveDirectory&lt;/A&gt;) I see that Heavy Forward is one option to install it, but respective table field is not checked.&lt;/P&gt;&lt;P&gt;Will Heavy Forwarder has to have the Search Head role enabled in order to query the Domain Controllers?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 10:42:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-SA-LDAPSearch-on-Splunk-Cloud/m-p/592866#M76551</guid>
      <dc:creator>b_chris21</dc:creator>
      <dc:date>2022-04-07T10:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to install SA_LDAPSearch on Splunk Cloud</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-SA-LDAPSearch-on-Splunk-Cloud/m-p/592868#M76552</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/41609"&gt;@b_chris21&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;no, the Search Head Role is only for Splunk queries, LDAP Search is a connector to extract data from AD and take in Splunk.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 10:47:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-SA-LDAPSearch-on-Splunk-Cloud/m-p/592868#M76552</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-04-07T10:47:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to install SA_LDAPSearch on Splunk Cloud</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-SA-LDAPSearch-on-Splunk-Cloud/m-p/592875#M76553</link>
      <description>&lt;P&gt;Hello Giuseppe,&lt;/P&gt;&lt;P&gt;thanks for your reply. So LDAPsearch is enough on my HF to connect to ADs and extract the info right?&lt;/P&gt;&lt;P&gt;Do you know if it periodically queries and extracts this info?&lt;/P&gt;&lt;P&gt;Many thanks.&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 11:35:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-SA-LDAPSearch-on-Splunk-Cloud/m-p/592875#M76553</guid>
      <dc:creator>b_chris21</dc:creator>
      <dc:date>2022-04-07T11:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to install SA_LDAPSearch on Splunk Cloud</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-SA-LDAPSearch-on-Splunk-Cloud/m-p/592882#M76554</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/41609"&gt;@b_chris21&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;yes, you can configure the frequency of querying.&lt;/P&gt;&lt;P&gt;It usually depends on many parameters: how frequently AD data are upgraded, how much license I accept to&amp;nbsp; consume for this updates, how much I want to load the AD.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 12:08:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-SA-LDAPSearch-on-Splunk-Cloud/m-p/592882#M76554</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-04-07T12:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to install SA_LDAPSearch on Splunk Cloud</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-SA-LDAPSearch-on-Splunk-Cloud/m-p/592886#M76555</link>
      <description>&lt;P class="lia-align-left"&gt;Grazie mille Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 12:17:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-SA-LDAPSearch-on-Splunk-Cloud/m-p/592886#M76555</guid>
      <dc:creator>b_chris21</dc:creator>
      <dc:date>2022-04-07T12:17:25Z</dc:date>
    </item>
  </channel>
</rss>

