All Apps and Add-ons

ldapsearch not returning list of all AD groups and users

gaurav_maniar
Builder

I'm trying to create a lookup of the domain, ad group and user using ldapsearch command from Active Direcotyr Add-on.

The below query is schduled as report and generates the lookup. If I manually verify the the data, some groups and all users from that groups are missing in the lookup.
| ldapsearch domain="test_domain" search="(&(objectClass=group))" attrs="sAMAccountName,member,groupType,sAMAccountType"
| search groupType=SECURITY_ENABLED
| spath
| rename sAMAccountName as sAMAccountName1
| mvexpand memebr
| ldapfetch domain="test_domain" dn="member" attrs="sAMAccountName,distinguishedName"

If I include the group names in the query, it generates the required lookup for the specified groups only.
| ldapsearch domain="test_domain" search="(&(objectClass=group)(|(cn=grp_prefix1*)(cn=grp_prefix2*))" attrs="sAMAccountName,member,groupType,sAMAccountType"
| search groupType=SECURITY_ENABLED
| spath
| rename sAMAccountName as sAMAccountName1
| mvexpand memebr
| ldapfetch domain="test_domain" dn="member" attrs="sAMAccountName,distinguishedName"

I'm not able to figure out, why the first query not returning the results for particular groups.
I also checked that, ignore/skipped groups is not due some outputlookup limit or alphabetical order.

Is there any limit on ldapfetch command for returning results?

Let me know if any other details are required.

0 Karma

to4kawa
Ultra Champion
| ldapsearch domain="test_domain" search="(&(objectClass=group)(|(cn=grp_prefix1*)(cn=grp_prefix2*)))" atrs="sAMAccountName,member,groupType,sAMAccountType" 
| search groupType=SECURITY_ENABLED 
| spath 
| rename sAMAccountName as sAMAccountName1 
| mvexpand memebr 
| ldapfetch domain="test_domain" dn="member" attrs="sAMAccountName,distinguishedName"

Hi, One parenthesis was missing.

0 Karma

gaurav_maniar
Builder

sorry, it was a typing mistake.

As I mentioned in the question, both queries are working fine.
The problem is the first query is supposed to return all groups, but due to some reasons, some groups are missing in the result.
When I execute the second query explicitly for those groups it is returning the results for these groups.
So why they are getting skipped in first query.

0 Karma

to4kawa
Ultra Champion

Does it mean that there is a user who is not objectClass = group but cn = grp_prefix1* or cn = grp_prefix2*?

0 Karma

gaurav_maniar
Builder

Mr. @woodcock , can you help with this one?

0 Karma
Get Updates on the Splunk Community!

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...

Security Highlights | January 2023 Newsletter

January 2023 Splunk Security Essentials (SSE) 3.7.0 ReleaseThe free Splunk Security Essentials (SSE) 3.7.0 app ...

Platform Highlights | January 2023 Newsletter

 January 2023Peace on Earth and Peace of Mind With Business ResilienceAll organizations can start the new year ...