Splunk Supporting Add-on for Active Directory 2.1.1
Splunk Enterprise 6.3.1
Running on Linux Centos 6.5
When I execute any LDAP search I have to wait for at least 5 minutes before I see results back! This is extremely slow. What can I do to troubleshoot this performance problem and improve the performance?
J. Napo Mokoetle
This has been broken for as long as it has existed.
I check with an os based ldapsearch and it instantly returns. As soon as you try to do it in the addon it's pretty much useless. We have a massive number of use cases for this and we have to resort to using external tools 😞
Frustrating! Let's hope someone from Splunk or otherwise will hear our cry and help us out of our specific ldapsearch related pain Lucas K 😉 .
just a quick question: do you use the LDPA Add-on or the SA-ldapsearch? I'm asking because you tagged the question with
Add-on for LDAP which does not provide a
ldapsearch command and listed the
Add-on for Active Directory as well...
Hi MuS, Thanks for your response. I'm using the SA-ldapsearch. I hope you can help resolve this performance problem.
Just to check if Splunk was the problem or NOT. I installed the Centos ldapsearch client and executed the same Active Directory search I've been trying through Splunk, and the AD results return in seconds.
So it seems to me the problem is with Splunk and not Active Directly or my system.
I strongly recommend you open a ticket on this issue as well.
The more customers that open tickets, the higher of a priority this becomes on the DEV side, and the more quickly you will get this issue addressed.