Splunk SOAR (f.k.a. Phantom)

Phantom integration with Microsoft LDAP

waleksandrowski
New Member

I have a problem with integration of Phantom with Active Directory. When I try to test connectivity with "Microsoft LDAP" app there is error with message:

App 'LDAP' started successfully (id: 1580900681102) on asset: 'pcb.lab'(id: 10)
Loaded action execution configuration
Ldap module initialized
1 action failed handle_action exception occurred. Error string: 'cannot concatenate 'str' and 'dict' objects'

Labels (2)
Tags (1)
0 Karma

sam_splunk
Splunk Employee
Splunk Employee
0 Karma

ericbrown1991
New Member

Any update here?

0 Karma

rneto
Splunk Employee
Splunk Employee

I had the same issue, but after upgrade the LDAP app version to 1.2.44, the connection worked fine.

0 Karma

TWiseOne
Path Finder

I can confirm that there is an Open, Critical JIRA ticket for this with Phantom engineering. Myself and a Customer have recently raised tickets with the exact same issue and were advised of the JIRA status.

0 Karma

satishclarios
New Member

@TWiseOne Any updates on this I'm getting the same error when I try to connect to LDAP.

0 Karma

ericbrown1991
New Member

Any update?

0 Karma

TWiseOne
Path Finder

@satishclarios If you are able to raise a support case I believe they have a patched version not quite GA yet. My customer was provided version 1.2.44 which resolved my issue. If you are not using this version on 4.8 I would recommend asking support.

0 Karma

satishclarios
New Member

Yes, they recommended to use the latest version of the app.

0 Karma

waleksandrowski
New Member

Hi,

there is no update but this integration works with Phantom version 4.6.18265. After update to version 4.8.23319 this error occurs. Probably this is problem with python version (python 3.6 in Phantom 4.8) but not sure.

Regards

0 Karma

barisaydogmusog
Loves-to-Learn

Hi,
I have come up with the same issue, any update?
Regards

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...