Splunk Search

Ldapsearch throwing spurious errors.

ifeldshteyn
Communicator

Hello,

I have a Search head cluster and an indexer cluster. 

When I am on one of the searchheads and run this ldapsearch command I get results. It works perfectly. 

 

| ldapsearch search="(&(objectCategory=Person)(objectClass=User)(lockoutTime>=1))" domain="MYDOMAIN.COM"  basedn="OU=Users,OU=NYHQ,OU=US,DC=MYDOMAIN,DC=com" 

 

However, all the indexers throw this spurious error, that doesn't seem to impact the results. 

 

[indexer1.mydomain.com] External search command 'ldapsearch' returned error code 1. Script output = " ERROR "KeyError at ""/opt/splunk/var/run/searchpeers/B8AB8EAB-1DD4-42C8-83DE-945995C604D4-1592589919/apps/SA-ldapsearch/bin/packages/splunklib/client.py"", line 1653 : u'ldap'" "

 

When I login directly to my indexers and execute the same ldap search locally, I don't receive any errors. 

SA-ldapsearch is configured on both indexers and searchheads. Each one has valid ldap.conf and passwords.conf  and present in $SPLUNK_HOME$etc/apps/SA-ldapsearch  . I am able to AD authenticate on all of the machines. 

Any idea why I am getting these spurious errors thrown on the searchheads but not the indexers?

Thanks!

Tags (2)
0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...