Getting Data In

SA-ldapsearch ldapgroup error

Hiattech
Explorer

We migrated our Splunk indexer from Ubuntu to RHEL recently. Everything appeared to go fine except for this one add-on. Initially, we were getting a different error. I ran fapolicyd-cli add file splunk to it and that error cleared but now we get this error. 

External search command "ldapgroup" returned error code 1. Script output = "error message=HTTPError at "/opt/splunk/etc/apps/SA-ldapsearch/bin/packages/splunklib/binding.py", line 1245 : HTTP 403 Forbidden - insufficient permission to access this resources."

I went in and did chown -R on the folder (and every other folder in the line including /opt/splunk) but that didn't fix it. The files and folders are all owned by splunk and have permission to run it. I have verified the firewall ports for 636 and 389 are open. We have tried to reinstall the add-on through the web interface and get a series of similar errors indicating that it can't copy a number of .py files over. Some do get copied though and most of the folders created. I'm at a bit of a loss...

 

Labels (1)
0 Karma
1 Solution

Hiattech
Explorer

We ended up disabling fapolicyd and testing the install again. It worked. After it was configured, we enabled fapolicyd and is still working.

View solution in original post

0 Karma

Hiattech
Explorer

We ended up disabling fapolicyd and testing the install again. It worked. After it was configured, we enabled fapolicyd and is still working.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

The error means that during execution of that script an exception was thrown at line 1245 because it tried to connect somewhere and got 403 as a response. It doesn't have anything to do with filesystem permissions.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...