All Apps and Add-ons

SA-ldapsearch upgrade to 2.0 ERROR on executing ldapfilter command

ollie920049
Path Finder

Hi,

Upgraded SA-ldapsearch app to 2.0 to remove the JAVA dependency. Now I am confronted with the following error when executing ldapfilter :

sourcetype=WinEventLog:Security earliest=-10m | ldapfilter domain="UBERIT" search="(name=$Account_Name$)" attrs="mobile"

External search command 'ldapfilter' returned error code 1. Script output = " ERROR "TypeError at ""C:\Program Files\Splunk\etc\apps\SA-ldapsearch\bin\packages\app\configuration.py"", line 177 : string indices must be integers, not unicode""

Any ideas what may be causing this?

Thanks in advance

0 Karma
1 Solution

javiergn
Super Champion

Managed to fix this by editing the new "default" profile and populating all the fields under the Configuration tab. For some reason it did not inherit anything from version 1

View solution in original post

ilirb
Path Finder

Hi,
I had the same problem after upgrading to 2.0.1. Completely reinstalling the SA-ldapsearch app (again ver 2.0.1), and creating two profiles inside ldap.conf (default and ours) with the same details configured - solved it in my case.

0 Karma

rsolutions
Path Finder

Upgrading to 2.0.1 fixed our issue.

0 Karma

javiergn
Super Champion

Managed to fix this by editing the new "default" profile and populating all the fields under the Configuration tab. For some reason it did not inherit anything from version 1

javiergn
Super Champion

Same here. Running ldap 2.0.1 on a Windows 6.2.1 deployment
No problems with the previous version of ldap though.

0 Karma

rsolutions
Path Finder

Hmm. Having the same issue with a brand new deployment....

0 Karma
Get Updates on the Splunk Community!

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...