<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error using sa-ldapsearch in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Error-using-sa-ldapsearch/m-p/349370#M94876</link>
    <description>&lt;P&gt;I am seeing the same error, did you ever figure out how to resolve?&lt;/P&gt;</description>
    <pubDate>Thu, 16 Aug 2018 16:41:13 GMT</pubDate>
    <dc:creator>mschlapfer</dc:creator>
    <dc:date>2018-08-16T16:41:13Z</dc:date>
    <item>
      <title>Error using sa-ldapsearch</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-using-sa-ldapsearch/m-p/349369#M94875</link>
      <description>&lt;P&gt;I'm using the lastest version of the app and Splunk 7.0.1 and I've tried every suggestion I can find on the Splunk website without any luck.  I get some variation of the error below.  I've gone as far as modifying the python the "default" option in the python scripts to point to my domain and all it does is change the error from ldap/default to ldap/"mydomain".   Anyone solved this mystery?&lt;/P&gt;

&lt;P&gt;External search command 'ldapgroup' returned error code 1. Script output = "error_message=Missing required value for alternatedomain in ldap/default&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 21:04:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-using-sa-ldapsearch/m-p/349369#M94875</guid>
      <dc:creator>jms112080</dc:creator>
      <dc:date>2018-04-18T21:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: Error using sa-ldapsearch</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-using-sa-ldapsearch/m-p/349370#M94876</link>
      <description>&lt;P&gt;I am seeing the same error, did you ever figure out how to resolve?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Aug 2018 16:41:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-using-sa-ldapsearch/m-p/349370#M94876</guid>
      <dc:creator>mschlapfer</dc:creator>
      <dc:date>2018-08-16T16:41:13Z</dc:date>
    </item>
    <item>
      <title>Re: Error using sa-ldapsearch</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-using-sa-ldapsearch/m-p/349371#M94877</link>
      <description>&lt;P&gt;I'm seeing this message as well. I have the below ldap.conf on the search head and indexer (we also have a deployment server we don't have it on) in our environment. I have tried having stanza [domain.com] in all caps and lowercase, as well as alternatedomain = DOMAIN in all caps and lowercase. The error message I'm receiving is "External search command 'ldapfetch' returned error code 1. Script output = "error_message=Missing required value for alternatedomain in ldap/DOMAIN. " I used DOMAIN in place of our actual domain name for the example it is correct in the ldap.conf file.&lt;/P&gt;

&lt;P&gt;[default]&lt;BR /&gt;
server = dc1.domain.com&lt;BR /&gt;
port = 389&lt;/P&gt;

&lt;P&gt;[domain.com]&lt;BR /&gt;
server = dc1.domain.com,dc2.domain.com&lt;BR /&gt;
port = 389&lt;BR /&gt;
ssl = false&lt;BR /&gt;
basedn = DC=naucom,DC=com&lt;BR /&gt;
binddn = CN=spl user,OU=Splunk,OU=System Accounts,OU=Departments and Categories,DC=domain,DC=com&lt;BR /&gt;
password = password&lt;BR /&gt;
alternatedomain = DOMAIN&lt;/P&gt;

&lt;P&gt;I'm assuming either you found the answer and didn;t post it or gave up. Either way it would be nice to resolve this issue so we can fully use Splunk App for Windows Infrastructure. &lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 16:58:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-using-sa-ldapsearch/m-p/349371#M94877</guid>
      <dc:creator>msteffes</dc:creator>
      <dc:date>2018-11-09T16:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: Error using sa-ldapsearch</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-using-sa-ldapsearch/m-p/349372#M94878</link>
      <description>&lt;P&gt;I read a similar post, and followed them.&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/172847/ldapfilter-is-giving-me-error-missing-required-val.html" target="_blank"&gt;https://answers.splunk.com/answers/172847/ldapfilter-is-giving-me-error-missing-required-val.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If you only have 1 domain, you can change that to default. It seems a work-around.&lt;BR /&gt;
local/ldap.conf&lt;BR /&gt;
[default]&lt;BR /&gt;
alternatedomain=DOMAIN&lt;BR /&gt;
basedn = dc=domain,dc=net&lt;BR /&gt;
binddn = svc_splunk_ldap&lt;BR /&gt;
server = ausdadc01.domain.net&lt;BR /&gt;
ssl = 0&lt;BR /&gt;
port = 389&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:54:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-using-sa-ldapsearch/m-p/349372#M94878</guid>
      <dc:creator>louismai</dc:creator>
      <dc:date>2020-09-30T01:54:52Z</dc:date>
    </item>
  </channel>
</rss>

