Hello,
for your information can't query anymore index with LDAP data (getting indexers memory errors) due to to OpenLDAP Add-on for Splunk (CIM) at https://splunkbase.splunk.com/app/3520/
Lookups : openldap_user_lookup & openldap_src_lookup