Splunk Search

Ldapsearch throwing spurious errors.

ifeldshteyn
Communicator

Hello,

I have a Search head cluster and an indexer cluster. 

When I am on one of the searchheads and run this ldapsearch command I get results. It works perfectly. 

 

| ldapsearch search="(&(objectCategory=Person)(objectClass=User)(lockoutTime>=1))" domain="MYDOMAIN.COM"  basedn="OU=Users,OU=NYHQ,OU=US,DC=MYDOMAIN,DC=com" 

 

However, all the indexers throw this spurious error, that doesn't seem to impact the results. 

 

[indexer1.mydomain.com] External search command 'ldapsearch' returned error code 1. Script output = " ERROR "KeyError at ""/opt/splunk/var/run/searchpeers/B8AB8EAB-1DD4-42C8-83DE-945995C604D4-1592589919/apps/SA-ldapsearch/bin/packages/splunklib/client.py"", line 1653 : u'ldap'" "

 

When I login directly to my indexers and execute the same ldap search locally, I don't receive any errors. 

SA-ldapsearch is configured on both indexers and searchheads. Each one has valid ldap.conf and passwords.conf  and present in $SPLUNK_HOME$etc/apps/SA-ldapsearch  . I am able to AD authenticate on all of the machines. 

Any idea why I am getting these spurious errors thrown on the searchheads but not the indexers?

Thanks!

Tags (2)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...