All Apps and Add-ons

SA-ldapsearch upgrade to 2.0 ERROR on executing ldapfilter command

ollie920049
Path Finder

Hi,

Upgraded SA-ldapsearch app to 2.0 to remove the JAVA dependency. Now I am confronted with the following error when executing ldapfilter :

sourcetype=WinEventLog:Security earliest=-10m | ldapfilter domain="UBERIT" search="(name=$Account_Name$)" attrs="mobile"

External search command 'ldapfilter' returned error code 1. Script output = " ERROR "TypeError at ""C:\Program Files\Splunk\etc\apps\SA-ldapsearch\bin\packages\app\configuration.py"", line 177 : string indices must be integers, not unicode""

Any ideas what may be causing this?

Thanks in advance

0 Karma
1 Solution

javiergn
Super Champion

Managed to fix this by editing the new "default" profile and populating all the fields under the Configuration tab. For some reason it did not inherit anything from version 1

View solution in original post

ilirb
Path Finder

Hi,
I had the same problem after upgrading to 2.0.1. Completely reinstalling the SA-ldapsearch app (again ver 2.0.1), and creating two profiles inside ldap.conf (default and ours) with the same details configured - solved it in my case.

0 Karma

rsolutions
Path Finder

Upgrading to 2.0.1 fixed our issue.

0 Karma

javiergn
Super Champion

Managed to fix this by editing the new "default" profile and populating all the fields under the Configuration tab. For some reason it did not inherit anything from version 1

javiergn
Super Champion

Same here. Running ldap 2.0.1 on a Windows 6.2.1 deployment
No problems with the previous version of ldap though.

0 Karma

rsolutions
Path Finder

Hmm. Having the same issue with a brand new deployment....

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...