All Apps and Add-ons

LDAP search no longer connecting

MaQ
New Member

Hi Team,

A former team configured the add-on for Active Directory and it has not been working for at least a few months now. The dashboards now display below error or "search auto-canceled".

External search command 'ldapsearch' returned error code 1. Script output = "error_message=socket connection error while opening: [Errno 111] Connection refused ".

Can you explain what this error means and what we can try to resolve it?

 

Thanks,

Mark.

c696a395-6f74-4775-a2e3-3be5532dae93.png

 

SplunkLDAPError.png

Labels (1)
0 Karma

johnhuang
Motivator

The server side (e.g. your corporate dmz/internet firewall) is blocking the inbound connection from Splunk Cloud to your LDAP server.

 

 

 

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...