Hi All
I had Splunk Support for Active Directory (SA-ldapsearch) configured and working in 6.2. I upgraded to 6.3 and it no longer functioned. I kept getting an error in the connection test saying "the default configuration stanza for ldap.conf is missing."
This was version 2.1. I have upgraded to the latest 2.1.1 and it still has not helped.
I have also completely removed SA-ldapsearch, restarted, reinstalled and re-keyed the configuration. We are still seeing the error above.
Has anyone else experienced this issue? How have you resolved it?
Thanks
Darren
That's a duplicate of TAG-9200 -- we're finally reproducing it and have a plan, but a support ticket is always in order to make sure we're catching your exact issue.
Just filed another ticket for this bug. Please escalate 😉
Further debugging reveals that the passwords.conf and the ldap.conf do not appear to be being replicated to the indexers in the config bundle that is pushed to the indexers, but at this stage i cannot work out why(the default and local versions of the files are not pushed to the indexers)
3 errors occurred while the search was executing. Therefore, search results might be incomplete. Hide errors.
External search command 'ldapsearch' returned error code 1. Script output = " ERROR Cannot find the configuration stanza for domain=xxxx in ldap.conf. "
[xxxx-i1] External search command 'ldapsearch' returned error code 1. Script output = " ERROR "KeyError at ""C:\Program Files\Splunk\var\run\searchpeers\xxxx-sh1-1443441409\apps\SA-ldapsearch\bin\packages\splunklib\client.py"", line 1653 : u'ldap'" "
[xxxx-i2] External search command 'ldapsearch' returned error code 1. Script output = " ERROR "KeyError at ""C:\Program Files\Splunk\var\run\searchpeers\xxxx-sh1-1443441409\apps\SA-ldapsearch\bin\packages\splunklib\client.py"", line 1653 : u'ldap'" "
anonymised ldap.conf:
[default]
alternatedomain = xxxx.xxx
basedn = DC=xxxx,DC=local
binddn = CN=splunk,OU=Service Account,OU=xxxx,OU=xxxxDC=xxxx,DC=xxx
port = 636
server = xxxx1.xxxx.local,xxxx2.xxxx.local
ssl = 1