<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic [update] Microsoft LDAP Phantom App in Splunk SOAR</title>
    <link>https://community.splunk.com/t5/Splunk-SOAR/Microsoft-LDAP-Phantom-App/m-p/525329#M498</link>
    <description>&lt;P&gt;Connection works OK, it seems that the vendor LDAP is not integrating with the current version of Phantom that only integrates with Microsoft vendor if I'm not wrong&lt;/P&gt;&lt;P&gt;How can we ask for adding integration with IBM LDAP?&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Mon, 19 Oct 2020 10:43:45 GMT</pubDate>
    <dc:creator>danieldelacasa</dc:creator>
    <dc:date>2020-10-19T10:43:45Z</dc:date>
    <item>
      <title>Microsoft LDAP Phantom App</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Microsoft-LDAP-Phantom-App/m-p/525047#M493</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We are trying to retrieve configuration both for AD and LDAP using the "Microsoft LDAP App" for Phantom using a new Playbook, but before that we want to get connection working.&lt;/P&gt;&lt;P&gt;We have an asset with our LDAP server (user and password working) but when we make the "Test connectivity" it shows us this message:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="danieldelacasa_0-1602849860361.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/11333iE8BBC963A9786A4F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="danieldelacasa_0-1602849860361.png" alt="danieldelacasa_0-1602849860361.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;There is no place to put the Base DN, how can we get the connection done?&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Fri, 16 Oct 2020 12:08:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Microsoft-LDAP-Phantom-App/m-p/525047#M493</guid>
      <dc:creator>danieldelacasa</dc:creator>
      <dc:date>2020-10-16T12:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft LDAP Phantom App</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Microsoft-LDAP-Phantom-App/m-p/525048#M494</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/227704"&gt;@danieldelacasa&lt;/a&gt;&amp;nbsp;I suspect this is a permissions issue in that the account being used to connect to LDAP isn't able to access the relevant part (Base DN) of your LDAP tree?&lt;BR /&gt;&lt;BR /&gt;There could also be the requirement from the LDAP server for SSL comms and it appears that failed. Or there could be a network issue between Phantom and LDAP over either port (389/636).&lt;BR /&gt;&lt;BR /&gt;All are worth checking but I would start with the permissions on your account being used to query LDAP.&lt;BR /&gt;&lt;BR /&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Oct 2020 12:17:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Microsoft-LDAP-Phantom-App/m-p/525048#M494</guid>
      <dc:creator>phanTom</dc:creator>
      <dc:date>2020-10-16T12:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft LDAP Phantom App</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Microsoft-LDAP-Phantom-App/m-p/525305#M495</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The credentials configured in Phantom App are the same as the ones in the current scripts we are running and want to replace by Phantom app so they are right, I also have tested them in my Python environment.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We are going to check comms betwenn Phantom and the LDAP server we want to connect to.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks for the information, we will let you know if we have solved the problem.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 08:26:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Microsoft-LDAP-Phantom-App/m-p/525305#M495</guid>
      <dc:creator>danieldelacasa</dc:creator>
      <dc:date>2020-10-19T08:26:02Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft LDAP Phantom App</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Microsoft-LDAP-Phantom-App/m-p/525326#M497</link>
      <description>&lt;P&gt;Connection works OK, it seems that the vendor LDAP is not integrating with the current version of Phantom that only integrates with Microsoft vendor if I'm not wrong&lt;/P&gt;&lt;P&gt;How can we ask for adding integration with IBM LDAP?&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 10:34:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Microsoft-LDAP-Phantom-App/m-p/525326#M497</guid>
      <dc:creator>danieldelacasa</dc:creator>
      <dc:date>2020-10-19T10:34:27Z</dc:date>
    </item>
    <item>
      <title>[update] Microsoft LDAP Phantom App</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Microsoft-LDAP-Phantom-App/m-p/525329#M498</link>
      <description>&lt;P&gt;Connection works OK, it seems that the vendor LDAP is not integrating with the current version of Phantom that only integrates with Microsoft vendor if I'm not wrong&lt;/P&gt;&lt;P&gt;How can we ask for adding integration with IBM LDAP?&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 10:43:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Microsoft-LDAP-Phantom-App/m-p/525329#M498</guid>
      <dc:creator>danieldelacasa</dc:creator>
      <dc:date>2020-10-19T10:43:45Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft LDAP Phantom App</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Microsoft-LDAP-Phantom-App/m-p/525342#M499</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/227704"&gt;@danieldelacasa&lt;/a&gt;&amp;nbsp;as far as I can see the app just uses the 'ldap' python library, so shouldn't be MS Only.&amp;nbsp;&lt;BR /&gt;What version of the App &amp;amp; Phantom are you using?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 12:33:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Microsoft-LDAP-Phantom-App/m-p/525342#M499</guid>
      <dc:creator>phanTom</dc:creator>
      <dc:date>2020-10-19T12:33:57Z</dc:date>
    </item>
  </channel>
</rss>

