Splunk SOAR (f.k.a. Phantom)

Why might the LDAP Get Users action not return all members?

gf13579
Communicator

When I run Get Users against the group named G-SomeGroup it returns just 1 result. The group contains 3 members

I can see from using PowerShell's Get-ADGroupMembers cmdlet that the group contains 3 users.

I'm running PowerShell as the same AD user I've configured the LDAP asset in Phantom to use.

The users in G-SomeGroup are direct members - no not members via nesting.

If I query G-SomeOtherGroup I see hundreds of members.

Any suggestions? Or logs to check?

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...