Splunk Enterprise Security

ldapsearch

deepdiver
Loves-to-Learn Everything

How would I find sAMAccountName(s) - more than one. I have tried boolean operators and(&) or(|) to no avail. Currently only one works. 
| ldapsearch domain=xxxx basedn="DC=xxxx,DC=xxxx" search="(&(objectClass=user)(sAMAccountName=specificuser))"

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

You want to find more than one user? Just add another sAMAccountName condition 🙂

The trick is that ldap filters use prefix notation, not infix one so you need to do it like this:

(&(objectClass=user)(|(sAMAccountName=specificuser)(sAMAccountName=otheruser)(sAMAccountName=thirduser)(and so on)))

I hope I got my parentheses right. 😄

Get Updates on the Splunk Community!

New This Month - Splunk Observability updates and improvements for faster ...

What’s New? This month, we’re delivering several enhancements across Splunk Observability Cloud for faster and ...

What's New in Splunk Cloud Platform 9.3.2411?

Hey Splunky People! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2411. This release ...

Buttercup Games: Further Dashboarding Techniques (Part 6)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...