Getting Data In

How can index ldif data?

abuschel
New Member

I have the export of an open ldap directory, in ldif format. I need to have this data indexed and somehow pivoted.

IS that possible?

Tags (2)
0 Karma

MuS
Legend

Hi abuschel,

basically Splunk is able to index any kind of human readable input, this includes a ldif file. Now for the tricky part, you must tell Splunk how to handle this file and what fields should be extracted and what their format is.

Start by reading the docs about adding data, add your file in the UI Manager and check the results, add any needed field extraction and proceed as needed with the created events.

hope this helps ...

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...