All Apps and Add-ons

No Data From Splunk Support for Active Directory

justin_coffi
Engager

I installed this application on a Windows 2008 R2 server (obviously x64). I've created the ldap.conf inside of the local subdirectory in the application's folder. The file looks like this

[lab.local]
server = 192.168.254.2
basedn = DC=lab,DC=local
binddn = CN=Splunk Searcher,CN=Managed Service Accounts,DC=lab,DC=local
password = <hidden>
alternatedomain = LAB

[default]
server = 192.168.254.2

I've also installed Java 1.7 SE (x86).

What exactly am I doing wrong?

0 Karma
1 Solution

ahall_splunk
Splunk Employee
Splunk Employee

I've just realized you have a mismatch between your Java version and the OS version. Have you tried installing the x64 version of Java 1.7.0u9?

View solution in original post

0 Karma

justin_coffi
Engager

Adrian's latest update to 1.1.6 resolved my issues.

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

I've just realized you have a mismatch between your Java version and the OS version. Have you tried installing the x64 version of Java 1.7.0u9?

0 Karma

justin_coffi
Engager

Adrian's latest update to 1.1.6 resolved my issues.

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

For those following along here - Justin had two problems:

1) 32-bit java on a 64-bit machine.

2) A posix:permissions issue, of which the less said the better as it is squarely aimed at Windows internals and is very messy.

I am working on a fix for both issues currently, and will release version 1.1.6 with a fix for both once I've finished testing them.

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

I just discovered a bug with the Windows connector in 1.7.0_u9 - they use a semi-colon instead of a colon on the class-path. I'm fixing that now and will post an update hopefully today.

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

Hi Justin - please reach out directly at ahall-at-splunk.com so we can set up a webex to discover the nature of the bug.

0 Karma

justin_coffi
Engager

Sadly, there is no change and still no logs.

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

Version 1.1.5 is now on Splunkbase

0 Karma

justin_coffi
Engager

Excellent. Thank you so much. After you've made the update, and I've updated, I'll test it again. If it works, I'll respond back here (for others later) and reward you the points.

0 Karma

justin_coffi
Engager

SA-ldapsearch version 1.1.4 and there isn't a log file by that name. I checked manually in "C:\Program Files\Splunk\var\log\splunk" and also searched the entire disk.

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee
  • What version of SA-ldapsearch are you using?
  • What does the log file (SA-ldapsearch.log) say?
0 Karma

justin_coffi
Engager

I've read the article and checked my settings using ADSIedit as well as Ldapbrowser. I am able to connect using LDAPbrowser using the same exact settings.

This is the query I'm running:

ldapsearch domain=LAB search="(objectClass=*)"

I don't receive any errors.

0 Karma

sdaniels
Splunk Employee
Splunk Employee

If you've been throught the docs i would also check this.

http://blogs.splunk.com/2012/10/21/splunk-app-for-active-directory-and-the-top-10-issues/

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...