<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunkd.log error : GetInt64Val: ldap_get_values error in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/splunkd-log-error-GetInt64Val-ldap-get-values-error/m-p/191853#M38221</link>
    <description>&lt;P&gt;I'm getting the same message&lt;/P&gt;</description>
    <pubDate>Thu, 02 Feb 2017 08:18:53 GMT</pubDate>
    <dc:creator>stefan1988</dc:creator>
    <dc:date>2017-02-02T08:18:53Z</dc:date>
    <item>
      <title>splunkd.log error : GetInt64Val: ldap_get_values error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunkd-log-error-GetInt64Val-ldap-get-values-error/m-p/191849#M38217</link>
      <description>&lt;P&gt;I am constantly getting the following message from splunk forwarder splunkd.log &lt;/P&gt;

&lt;P&gt;03-17-2014 11:38:28.245 -0700 WARN  ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe""  splunk-regmon - SysmonMigrator::read - 'sysmon.conf' was not found, no migration is required.&lt;BR /&gt;
03-17-2014 11:58:32.247 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::GetInt64Val: ldap_get_values error&lt;BR /&gt;
03-17-2014 11:58:32.247 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.&lt;BR /&gt;
03-17-2014 11:58:32.247 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::GetInt64Val: ldap_get_values error&lt;BR /&gt;
03-17-2014 11:58:32.247 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.&lt;BR /&gt;
03-17-2014 12:01:17.610 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::GetInt64Val: ldap_get_values error&lt;BR /&gt;
03-17-2014 12:01:17.610 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.&lt;BR /&gt;
03-17-2014 12:12:15.646 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::GetInt64Val: ldap_get_values error&lt;BR /&gt;
03-17-2014 12:12:15.646 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.&lt;BR /&gt;
03-17-2014 12:15:01.594 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::GetInt64Val: ldap_get_values error&lt;BR /&gt;
03-17-2014 12:15:01.594 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.&lt;BR /&gt;
03-17-2014 12:15:01.594 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::GetInt64Val: ldap_get_values error&lt;BR /&gt;
03-17-2014 12:15:01.594 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.&lt;BR /&gt;
03-17-2014 12:16:33.793 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::GetInt64Val: ldap_get_values error&lt;BR /&gt;
03-17-2014 12:16:33.793 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.&lt;BR /&gt;
03-17-2014 12:18:02.373 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::GetInt64Val: ldap_get_values error&lt;BR /&gt;
03-17-2014 12:18:02.373 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.&lt;BR /&gt;
03-17-2014 12:18:02.373 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::GetInt64Val: ldap_get_values error&lt;BR /&gt;
03-17-2014 12:18:02.373 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.&lt;BR /&gt;
03-17-2014 12:20:46.566 -0700 INFO  WatchedFile - Logfile truncated while open, original pathname file='C:\Users\rq113d\Desktop\test1\IVTRUpdateLog_2014-03-16 20-101.txt', will begin reading from start.&lt;BR /&gt;
03-17-2014 12:24:25.501 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::GetInt64Val: ldap_get_values error&lt;BR /&gt;
03-17-2014 12:24:25.501 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.&lt;BR /&gt;
03-17-2014 12:24:25.501 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::GetInt64Val: ldap_get_values error&lt;BR /&gt;
03-17-2014 12:24:25.501 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.&lt;BR /&gt;
03-17-2014 12:39:50.170 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::GetInt64Val: ldap_get_values error&lt;/P&gt;

&lt;P&gt;Is anyone having similar issue? what this error indicates. Any suggestions? &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:09:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunkd-log-error-GetInt64Val-ldap-get-values-error/m-p/191849#M38217</guid>
      <dc:creator>CSabhaya</dc:creator>
      <dc:date>2020-09-28T16:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: splunkd.log error : GetInt64Val: ldap_get_values error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunkd-log-error-GetInt64Val-ldap-get-values-error/m-p/191850#M38218</link>
      <description>&lt;P&gt;We are facing a similar issue as well. We are trying to read windows event logs from a machine which has a Splunk forwarder installed version 5.0.1. The inputs.conf file is as below:&lt;/P&gt;

&lt;P&gt;[WinEventLog://Application]&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
current_only = 0&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
index = mag_nprod&lt;BR /&gt;
start_from = oldest&lt;/P&gt;

&lt;P&gt;[WinEventLog://System]&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
current_only = 0&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
index = mag_nprod&lt;BR /&gt;
start_from = oldest&lt;/P&gt;

&lt;P&gt;The following error message is present in the Splunkd logs:&lt;/P&gt;

&lt;P&gt;10-09-2014 15:47:22.660 +0100 ERROR ExecProcessor - message from "E:\tools\SplunkForwarder\bin\splunk-admon.exe" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.&lt;BR /&gt;
10-09-2014 15:47:22.660 +0100 ERROR ExecProcessor - message from "E:\tools\SplunkForwarder\bin\splunk-admon.exe" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.&lt;BR /&gt;
10-09-2014 15:47:19.034 +0100 ERROR ExecProcessor - message from "E:\tools\SplunkForwarder\bin\splunk-admon.exe" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.&lt;BR /&gt;
10-09-2014 15:47:18.409 +0100 ERROR ExecProcessor - message from "E:\tools\SplunkForwarder\bin\splunk-admon.exe" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.&lt;BR /&gt;
10-09-2014 15:46:51.783 +0100 ERROR ExecProcessor - message from "E:\tools\SplunkForwarder\bin\splunk-admon.exe" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.&lt;BR /&gt;
10-09-2014 15:46:27.158 +0100 ERROR ExecProcessor - message from "E:\tools\SplunkForwarder\bin\splunk-admon.exe" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.&lt;/P&gt;

&lt;P&gt;Any suggestions please?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:50:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunkd-log-error-GetInt64Val-ldap-get-values-error/m-p/191850#M38218</guid>
      <dc:creator>ankeetashet</dc:creator>
      <dc:date>2020-09-28T17:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: splunkd.log error : GetInt64Val: ldap_get_values error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunkd-log-error-GetInt64Val-ldap-get-values-error/m-p/191851#M38219</link>
      <description>&lt;P&gt;Was there ever an answer to this? I am having the same problem. Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2015 17:16:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunkd-log-error-GetInt64Val-ldap-get-values-error/m-p/191851#M38219</guid>
      <dc:creator>e2eadmin</dc:creator>
      <dc:date>2015-01-07T17:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: splunkd.log error : GetInt64Val: ldap_get_values error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunkd-log-error-GetInt64Val-ldap-get-values-error/m-p/191852#M38220</link>
      <description>&lt;P&gt;Has there been answer found out for this? I am having the same problem?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2016 03:00:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunkd-log-error-GetInt64Val-ldap-get-values-error/m-p/191852#M38220</guid>
      <dc:creator>ccraft_splunk</dc:creator>
      <dc:date>2016-06-21T03:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: splunkd.log error : GetInt64Val: ldap_get_values error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunkd-log-error-GetInt64Val-ldap-get-values-error/m-p/191853#M38221</link>
      <description>&lt;P&gt;I'm getting the same message&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2017 08:18:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunkd-log-error-GetInt64Val-ldap-get-values-error/m-p/191853#M38221</guid>
      <dc:creator>stefan1988</dc:creator>
      <dc:date>2017-02-02T08:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: splunkd.log error : GetInt64Val: ldap_get_values error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunkd-log-error-GetInt64Val-ldap-get-values-error/m-p/191854#M38222</link>
      <description>&lt;P&gt;bump&lt;/P&gt;

&lt;P&gt;we are too&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 20:16:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunkd-log-error-GetInt64Val-ldap-get-values-error/m-p/191854#M38222</guid>
      <dc:creator>davidboose</dc:creator>
      <dc:date>2017-02-03T20:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: splunkd.log error : GetInt64Val: ldap_get_values error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunkd-log-error-GetInt64Val-ldap-get-values-error/m-p/191855#M38223</link>
      <description>&lt;P&gt;can you check inputs.conf and admon.conf to see that stanzas not configured by you are set to 'disabled=1'&lt;/P&gt;

&lt;P&gt;This error shows up because Active Directory query is not returning required values.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 23:09:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunkd-log-error-GetInt64Val-ldap-get-values-error/m-p/191855#M38223</guid>
      <dc:creator>adhoke_splunk</dc:creator>
      <dc:date>2017-02-03T23:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: splunkd.log error : GetInt64Val: ldap_get_values error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunkd-log-error-GetInt64Val-ldap-get-values-error/m-p/191856#M38224</link>
      <description>&lt;P&gt;I got this error as well:&lt;/P&gt;

&lt;P&gt;10-09-2014 15:46:27.158 +0100 ERROR ExecProcessor - message from "E:\tools\SplunkForwarder\bin\splunk-admon.exe" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.&lt;/P&gt;

&lt;P&gt;Had checked the \bin directory, the splunk-admon.exe is not missing.&lt;/P&gt;

&lt;P&gt;Not sure what to do next though.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2017 03:37:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunkd-log-error-GetInt64Val-ldap-get-values-error/m-p/191856#M38224</guid>
      <dc:creator>season88481</dc:creator>
      <dc:date>2017-02-28T03:37:06Z</dc:date>
    </item>
  </channel>
</rss>

