Splunk SOAR (f.k.a. Phantom)

Why might the LDAP Get Users action not return all members?


When I run Get Users against the group named G-SomeGroup it returns just 1 result. The group contains 3 members

I can see from using PowerShell's Get-ADGroupMembers cmdlet that the group contains 3 users.

I'm running PowerShell as the same AD user I've configured the LDAP asset in Phantom to use.

The users in G-SomeGroup are direct members - no not members via nesting.

If I query G-SomeOtherGroup I see hundreds of members.

Any suggestions? Or logs to check?

Labels (2)
0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!