All Apps and Add-ons

Security Audit issue in Splunk App for Active Directory

Nguyen_Ma
Engager

Hi all,

When I access to any field of Security -> Audit in Splunk app for Active Directory. I received an error message [command="ldapsearch", IO::Socket::INET: connect: Connection refused]. I don't have much experience with Perl. Anyone help me by any advise?

Thank you so much

0 Karma
1 Solution

Drainy
Champion

Have you verified the ldap server details in the config file? If you entered the wrong details then its quite likely you would receive a connection refused. Also if a local firewall is restricting access out of the local machine to the remote ldap server.

View solution in original post

ahall_splunk
Splunk Employee
Splunk Employee

Following on from the excellent answer from Drainy, it's common to get a message "No matching fields exist" in the Administrator Audit - the page does six searches - if one of the searches has no results, then you get the error.

On your user audit page, it means that it could not find the username that you typed in. Make sure you are typing in the sAMAccountName of the account you want to view.

Drainy
Champion

Have you verified the ldap server details in the config file? If you entered the wrong details then its quite likely you would receive a connection refused. Also if a local firewall is restricting access out of the local machine to the remote ldap server.

Drainy
Champion

You need to verify your object definitions. It sounds like it cannot find them on the remote LDAP server

Nguyen_Ma
Engager

Thank for your answer, I've just configured activedirectory.conf file and got new issue. I access to Security -> Audit -> Administrator Audit and got a message "No matching fields exist". Then I go to User Audit, I got an error message [command="ldapsearch", No such object]. My config file as below:

[server]
ldapurl=ldap://192.168.81.230
basedn=dc=vsslab,dc=com
bindas=cn=Administrator,cn=Users,dc=vsslab,dc=com
password=*******

My domain is vsslab.com

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...