I'm having success with the add-on, but only when I'm in the "Splunk Supporting Add-on for Active Directory" app. When I copy/paste the string into the default Search app it fails with:
"External search command 'ldapfilter' returned error code 1. Script output = " ERROR "Invalid credentials for the user with binddn=""cn=read-only-admin,dc=example,dc=com"". Please correct and test your SA-ldapsearch credentials in the context of domain=""default""" ""
I've checked and double-checked the settings, all appears fine. Have a case open with tech. support, they are unresponsive. From other posts it seems like this is a fairly flakey app, I'm on version 2.1.1, Splunk 6.2.3
Answering my own question: Yes, it does work in default/regular Search app. Installed on another search head and it's working fine.