All Apps and Add-ons

ldapfilter is giving me ERROR Missing required value for server in ldap/mydomain but ldapsearch works

rbacker527
Engager

Search string |ldapsearch domain=mydomain search="(sAMAccountNAme=username)" attrs="cn" works but when I switch it to a ldapfilter I get the error ERROR Missing required value for server in ldap/mydomain
|ldapfetch domain=mydomain search="(sAMAccountNAme=username" attrs="cn"

1 Solution

ktwombley
Explorer

In my environment we have 1 domain set up. I worked around this issue by copying all the info from the configuration for our domain into the configuration for the default domain.

It's not an answer, but it might be a work-around if you only need to have a single domain configured for SA-ldapsearch.

View solution in original post

pkatti
Splunk Employee
Splunk Employee

Hi,
This is a late post but try this - for ldapfetch, ldapfilter and ldapgroup make sure you have a default stanza in your ldap.conf. this default stanza should point to the global catalog server
refer: https://docs.splunk.com/Documentation/SA-LdapSearch/2.1.4/User/Theldap.confconfigurationfile#.27Defa...
Also, make sure you add an alternatedomain to this default stanza.
Make sure this alternatedomain is not repeated in any other stanza, otherwise you would run into duplicate alternatedomain error.

0 Karma

ktwombley
Explorer

In my environment we have 1 domain set up. I worked around this issue by copying all the info from the configuration for our domain into the configuration for the default domain.

It's not an answer, but it might be a work-around if you only need to have a single domain configured for SA-ldapsearch.

lior_g
Explorer

Worked for me, I tried the adding "local = true" to every stanza in commands.conf solution at first, it resolved my issues with the "Test Connection" button not working but then I got the same error message - "ERROR Missing required value for alternatedomain..."

0 Karma

MuS
Legend

Hi rbacker527,

sorry it took a bit longer, but I just realized you're NOT using my LDAP Add-on but the SA-ldapsearch. Because my Add-on does not have any ldapsearch nor ldapfilter nor ldapfetch command; it has only the ldap command. So I will re-tag is for the SA-ldapsearch.

cheers, MuS

0 Karma

sbochniewicz
Path Finder

I am having the same issue ldapfilter does not honor the domain="xyz" always uses the default.

0 Karma

jeff
Contributor

I'm also having that issue, but in my case it's giving

ERROR Missing required value for alternatedomain in ldap/mydomain.

In my case, I need to support multiple domains, so simply using default won't work well for me.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...