All Apps and Add-ons

ldapfilter is giving me ERROR Missing required value for server in ldap/mydomain but ldapsearch works

rbacker527
Engager

Search string |ldapsearch domain=mydomain search="(sAMAccountNAme=username)" attrs="cn" works but when I switch it to a ldapfilter I get the error ERROR Missing required value for server in ldap/mydomain
|ldapfetch domain=mydomain search="(sAMAccountNAme=username" attrs="cn"

1 Solution

ktwombley
Explorer

In my environment we have 1 domain set up. I worked around this issue by copying all the info from the configuration for our domain into the configuration for the default domain.

It's not an answer, but it might be a work-around if you only need to have a single domain configured for SA-ldapsearch.

View solution in original post

pkatti
Splunk Employee
Splunk Employee

Hi,
This is a late post but try this - for ldapfetch, ldapfilter and ldapgroup make sure you have a default stanza in your ldap.conf. this default stanza should point to the global catalog server
refer: https://docs.splunk.com/Documentation/SA-LdapSearch/2.1.4/User/Theldap.confconfigurationfile#.27Defa...
Also, make sure you add an alternatedomain to this default stanza.
Make sure this alternatedomain is not repeated in any other stanza, otherwise you would run into duplicate alternatedomain error.

0 Karma

ktwombley
Explorer

In my environment we have 1 domain set up. I worked around this issue by copying all the info from the configuration for our domain into the configuration for the default domain.

It's not an answer, but it might be a work-around if you only need to have a single domain configured for SA-ldapsearch.

lior_g
Explorer

Worked for me, I tried the adding "local = true" to every stanza in commands.conf solution at first, it resolved my issues with the "Test Connection" button not working but then I got the same error message - "ERROR Missing required value for alternatedomain..."

0 Karma

MuS
Legend

Hi rbacker527,

sorry it took a bit longer, but I just realized you're NOT using my LDAP Add-on but the SA-ldapsearch. Because my Add-on does not have any ldapsearch nor ldapfilter nor ldapfetch command; it has only the ldap command. So I will re-tag is for the SA-ldapsearch.

cheers, MuS

0 Karma

sbochniewicz
Path Finder

I am having the same issue ldapfilter does not honor the domain="xyz" always uses the default.

0 Karma

jeff
Contributor

I'm also having that issue, but in my case it's giving

ERROR Missing required value for alternatedomain in ldap/mydomain.

In my case, I need to support multiple domains, so simply using default won't work well for me.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...