Hello all,
The command 
| rest /services/authentication/current-context 
will return some fields like username, email, realname, etc..
I want to get other fields on LDAP like Telephone Number, SIP address, etc..
Is it possible?
Thanks
 
		
		
		
		
		
	
			
		
		
			
					
		You'll need a secondary data source, e.g. ldapsearch, to retrieve that information, use the username returned by current-context as a filter.
 
		
		
		
		
		
	
			
		
		
			
					
		You'll need a secondary data source, e.g. ldapsearch, to retrieve that information, use the username returned by current-context as a filter.
 
		
		
		
		
		
	
			
		
		
			
					
		SA-ldapsearch runs on linux splunk servers.
If you don't have AD, consider https://splunkbase.splunk.com/app/3872/
after tried again, i finally made this works. Thanks a lot!
i already looked into this, unfortunately my server is linux so this solution is not compatible, do you have other suggestion for linux? Thanks
 
					
				
		
Well, you can always define regular expressions to fetch needed field value, are you looking to extract ALL fields automatically? There is limitations on that
I want to get these 2 fields SipAddress and Phone, could you please advise what regex to use and where can I apply it?
Thanks
 
					
				
		
can you post a sample of your events as they appear in splunk?
I think you might have misunderstood my question, and sorry as I wasn't clear enough.
I want to get additional information which does NOT exist in current-context,
When the user authenticates using LDAP username/password, Splunk does the ldap lookup and returns some of standard fields like username, email, realname, etc..
Besides those fields, i want to get something else which is missing, for example Phone and SipAddress
