Splunk Enterprise Security

Combine base search with LDAP search

d3ll0211
Loves-to-Learn

I am having difficulty combining two individual searches.  I have the following ldap search that lists the member names from group1 or group2

| ldapsearch search="(&(objectClass=group)(|(cn=group1)(cn=group2)))" attrs="member"
| ldapfetch dn=member attrs="givenName, sn"
| eval user=givenName." ".sn
| table user

I want the ldap search to list the member names when it meets the criteria of the base search:

index=myindex EventCode=5136 action=success name="A directory service object was modified"

How do I combine the two?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...