All Apps and Add-ons

Splunk Support for Active Directory version 2.0.0 not working with multiple LDAP servers in one stanza (getaddrinfo failed)

mikaelbje
Motivator

I just upgraded the Splunk Support for Active Directory add-on to version 2.0.0. I tried re-entering the password in the configuration page for the domain and "Test connection" but no results were found. Testing the same search in the search bar showed:

[Errno 11001] getaddrinfo failed

It turns out that version 2.0.0 no longer supports multiple servers delimited by ;, so I changed my server stanza from

server = server1.example.com;server2.example.com;server3.example.com;server4.example.com

to

server = server1.example.com

which works, but you lose the reliability with multiple servers.

I'm posting this in case someone else has the same issue.

0 Karma

hlarimer
Communicator

If I remember right when I upgraded this app I had to switch the ; to , when using multiple LDAP servers. Try to change that in your configuration and let me know if it works.

sloshburch
Ultra Champion

Documentation implies that it should work. http://docs.splunk.com/Documentation/SA-LdapSearch/latest/User/ConfiguretheSplunkSupportingAdd-onfor...

Did you open a case for this?

I do see that multiple trees/domains are not supported. But your post is specific to servers. Different issue, right?,The documentation implies that it does support multiple servers: http://docs.splunk.com/Documentation/SA-LdapSearch/latest/User/ConfiguretheSplunkSupportingAdd-onfor....
If that's still an issue, did you try opening a case with support?

0 Karma

mikaelbje
Motivator

Unless a new version is out then it doesn't work. Didn't open a case as I expected the dev to monitor the tag here on Splunk Answers.

0 Karma

sloshburch
Ultra Champion

I've seen some devs will follow the tags, but some are just too busy with the feature request queue that's already in the pipeline. I would encourage you to formally open a case. I've had better luck with that producing resolution.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...