How to make ldap search data searchable in Splunk Enterprise. I was able to run the following search within the add-on but when I collect the data the fields are no longer extracted.
| ldapsearch domain=default search="(objectClass=user)"
| collect index=summary
Could you tell me what I need to do to make this work or if it is even possible without creating a table of every field.
It should work, but have you tried this?
| ldapsearch domain=default search="(objectClass=user)"
| table *
| collect index=summary
Thank you. This did work for me!