I have a search below that works fine, but I would like to add a wildcard to it.
This search works
| ldapsearch domain=mydomain.com search=(&(objectClass=computer)(memberOf="CN=Patch1, OU=Patches,OU=Wintel,DC=Mydomain,DC=com)) attrs=name
I would like to do something like below, but it does not show any results with the wildcard.
| ldapsearch domain=mydomain.com search=(&(objectClass=computer)(memberOf="CN=Patch*, OU=Patches,OU=Wintel,DC=Mydomain,DC=com)) attrs=name
Hey Chadman,
Try something like this:
search="(CN=Patch*)"
and keep adding to if that is working in your environment.
Or you can get a bit more creative (not sure if this will work for you, you may want to try creating a Lookup that you can pull the data from, to search):
| ldapsearch domain=mydomain.com search=objectClass=computer | search memberOf="(CN=Patch*, OU=Patches,OU=Wintel,DC=Mydomain,DC=com)"
This issue has been resolved: https://docs.splunk.com/Documentation/SA-LdapSearch/2.2.1/User/ReleaseNotes#Fixed_issues
Hey Chadman,
Try something like this:
search="(CN=Patch*)"
and keep adding to if that is working in your environment.
Or you can get a bit more creative (not sure if this will work for you, you may want to try creating a Lookup that you can pull the data from, to search):
| ldapsearch domain=mydomain.com search=objectClass=computer | search memberOf="(CN=Patch*, OU=Patches,OU=Wintel,DC=Mydomain,DC=com)"
hos_2,
That does kind of work, but how can I do something like below to narrow down the search?
search="(CN=Patch*)(OU=Wintel)"
I believe you need to use the and filtercomp "&". Still learning myself, but might try:
search=(&(CN=Patch*)&(OU=Wintel))
Maybe something like this?
search memberOf="CN=Patch*" AND memberOf=(OU=Patches,OU=Wintel,DC=Mydomain,DC=com)
Cant get that to work, syntax might be wrong. I have tried a couple variations. I also tried to add basedn=(OU=Patches,OU=Wintel,DC=Mydomain,DC=com) thinking that would limit the scope of my search, but it's not.
Yeah we had similar issues with the data, our work around was to just gather everything in a lookup daily, then run searches off the lookup tables.
Thanks. I might look into that also. I was hopping to avoid having another process to create the lookup table. I also posted another question similar, but without wild cards.