Getting Data In

java problem with active-directory

perlish
Communicator

I want to use the splunk app for active directory.I have installed the central splunk instance and ad app in two systems,one is win2008,the other is centos 6.2.But I come across problems within two system.The following is details:
1、win 2008 system
OS:Microsoft Windows Server 2008 R2 Enterprise
JAVA VERSION:java version "1.7.0_45"
Java(TM) SE Runtime Environment (build 1.7.0_45-b18)
Java HotSpot(TM) 64-Bit Server VM (build 24.45-b08, mixed mode)
PROBLEM:The ad app can't load my domain information,and when I use the "Group Audit",it reports errors like "External search command 'ldapsearch' returned error code 1.ERROR: java.lang.NullPointerException: null"

2、Centos 6.2 system
OS:CentOS release 6.2 (Final)
JAVA VERSION:java version "1.7.0_45"
Java(TM) SE Runtime Environment (build 1.7.0_45-b18)
Java HotSpot(TM) 64-Bit Server VM (build 24.45-b08, mixed mode)
PROBLEM:The app can load my domain information,but when I use "Group Audit",it report errors like External"search command 'ldapsearch' returned error code 1.ERROR: com.unboundid.ldap.sdk.LDAPException: Unable to establish a connection to any server in the fastest connect set because connection attempts failed in all servers."

I think all these is because the java ,but how can I solve them?
0 Karma

Adrian
Path Finder

I would start by reviewing this troubleshooting section of the documentation related to the Splunk App for AD.

0 Karma
Get Updates on the Splunk Community!

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...

Join Us at the Builder Bar at .conf24 – Empowering Innovation and Collaboration

What is the Builder Bar? The Builder Bar is more than just a place; it's a hub of creativity, collaboration, ...

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...