Hi, I have a "|dbquery" which returns an User ID, and I want to use this UserID to find an User's location bia "|ldapsearch", splunk doesn't allow these two real time search together in one search, is there any other way I can do this ?
Do you need to run those two as realtime searches?
the below should do
http://answers.splunk.com/answers/86847/splunk-query-with-ldap-info