I have the export of an open ldap directory, in ldif format. I need to have this data indexed and somehow pivoted.
IS that possible?
basically Splunk is able to index any kind of human readable input, this includes a ldif file. Now for the tricky part, you must tell Splunk how to handle this file and what fields should be extracted and what their format is.
Start by reading the docs about adding data, add your file in the UI Manager and check the results, add any needed field extraction and proceed as needed with the created events.
hope this helps ...