<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ldapsearch Error under user audit &amp;quot;Splunk for Windows Server Active Directory App&amp;quot; in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/ldapsearch-Error-under-user-audit-quot-Splunk-for-Windows-Server/m-p/94262#M19606</link>
    <description>&lt;P&gt;Running into the same problem here; though I'm still at the initial error - I'll try configuring Perl, but would expect to run into the second issue as well.  My install is running on Debian Squeeze.&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jul 2012 21:25:09 GMT</pubDate>
    <dc:creator>itfpmhtcom</dc:creator>
    <dc:date>2012-07-19T21:25:09Z</dc:date>
    <item>
      <title>ldapsearch Error under user audit "Splunk for Windows Server Active Directory App"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ldapsearch-Error-under-user-audit-quot-Splunk-for-Windows-Server/m-p/94259#M19603</link>
      <description>&lt;P&gt;Need to some help getting my install of "Splunk for Windows Server Active Directory" app working.  when I run the "User login Failures" search and click on a user that has a failed logon attempt I get these errors...&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;"Lookup table 'HostInfo' is empty"&lt;/LI&gt;
&lt;LI&gt;"No Matching fields exist" &lt;/LI&gt;
&lt;LI&gt;"Error in 'script': Getinfo probe failed for external search command 'ldapsearch'"&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;The last error is in Red. &lt;/P&gt;

&lt;P&gt;Ideas?&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Eric&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2012 23:15:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ldapsearch-Error-under-user-audit-quot-Splunk-for-Windows-Server/m-p/94259#M19603</guid>
      <dc:creator>Eric</dc:creator>
      <dc:date>2012-07-09T23:15:01Z</dc:date>
    </item>
    <item>
      <title>Re: ldapsearch Error under user audit "Splunk for Windows Server Active Directory App"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ldapsearch-Error-under-user-audit-quot-Splunk-for-Windows-Server/m-p/94260#M19604</link>
      <description>&lt;P&gt;Okay so I have moved a little further with this issue.. I did not have Perl configured all the way, but now I get error 255 when Perl tries to run.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2012 02:15:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ldapsearch-Error-under-user-audit-quot-Splunk-for-Windows-Server/m-p/94260#M19604</guid>
      <dc:creator>Eric</dc:creator>
      <dc:date>2012-07-10T02:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: ldapsearch Error under user audit "Splunk for Windows Server Active Directory App"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ldapsearch-Error-under-user-audit-quot-Splunk-for-Windows-Server/m-p/94261#M19605</link>
      <description>&lt;P&gt;Moved my splunk install to *nix and still cant get this thing to work. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2012 20:07:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ldapsearch-Error-under-user-audit-quot-Splunk-for-Windows-Server/m-p/94261#M19605</guid>
      <dc:creator>Eric</dc:creator>
      <dc:date>2012-07-10T20:07:09Z</dc:date>
    </item>
    <item>
      <title>Re: ldapsearch Error under user audit "Splunk for Windows Server Active Directory App"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ldapsearch-Error-under-user-audit-quot-Splunk-for-Windows-Server/m-p/94262#M19606</link>
      <description>&lt;P&gt;Running into the same problem here; though I'm still at the initial error - I'll try configuring Perl, but would expect to run into the second issue as well.  My install is running on Debian Squeeze.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2012 21:25:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ldapsearch-Error-under-user-audit-quot-Splunk-for-Windows-Server/m-p/94262#M19606</guid>
      <dc:creator>itfpmhtcom</dc:creator>
      <dc:date>2012-07-19T21:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: ldapsearch Error under user audit "Splunk for Windows Server Active Directory App"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ldapsearch-Error-under-user-audit-quot-Splunk-for-Windows-Server/m-p/94263#M19607</link>
      <description>&lt;P&gt;I'm having a similar isuse but the error only occurs when I try to run any of the Security &amp;gt; Audit &amp;gt; Reports.&lt;/P&gt;

&lt;P&gt;I receive the error in red across the top:&lt;/P&gt;

&lt;P&gt;Error in 'script': Getinfo probe failed for external search command 'ldapsearch'&lt;/P&gt;

&lt;P&gt;Any suggestions are apprecaited.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2012 13:12:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ldapsearch-Error-under-user-audit-quot-Splunk-for-Windows-Server/m-p/94263#M19607</guid>
      <dc:creator>splunkn</dc:creator>
      <dc:date>2012-08-10T13:12:56Z</dc:date>
    </item>
    <item>
      <title>Re: ldapsearch Error under user audit "Splunk for Windows Server Active Directory App"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ldapsearch-Error-under-user-audit-quot-Splunk-for-Windows-Server/m-p/94264#M19608</link>
      <description>&lt;P&gt;Current known issues&lt;BR /&gt;
The LDAP search commands (that install on the central Splunk App for&lt;BR /&gt;
Active Directory instance) do not work on Windows operating systems,&lt;BR /&gt;
owing to platform compatibility issues. As a workaround, build your central&lt;BR /&gt;
Splunk instance around the Linux platform (MSAD-73).&lt;BR /&gt;
·&lt;BR /&gt;
The LDAP search commands do not work for sub-domains in an AD forest&lt;BR /&gt;
(MSAD-105).&lt;BR /&gt;
·&lt;BR /&gt;
Older versions of the universal forwarder might not correctly get some&lt;BR /&gt;
Windows events. To fix this issue, upgrade your forwarders to the latest&lt;BR /&gt;
version. (SPL-51312)&lt;BR /&gt;
·&lt;BR /&gt;
52&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2012 13:23:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ldapsearch-Error-under-user-audit-quot-Splunk-for-Windows-Server/m-p/94264#M19608</guid>
      <dc:creator>splunkn</dc:creator>
      <dc:date>2012-08-10T13:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: ldapsearch Error under user audit "Splunk for Windows Server Active Directory App"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ldapsearch-Error-under-user-audit-quot-Splunk-for-Windows-Server/m-p/94265#M19609</link>
      <description>&lt;P&gt;I'm running this on Windows, so I think I answered my own question.  Hopefully this can help someone else who is having the same issues.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2012 13:24:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ldapsearch-Error-under-user-audit-quot-Splunk-for-Windows-Server/m-p/94265#M19609</guid>
      <dc:creator>splunkn</dc:creator>
      <dc:date>2012-08-10T13:24:24Z</dc:date>
    </item>
  </channel>
</rss>

