Splunk® Supporting Add-on for Active Directory

Deploy and Use the Splunk Supporting Add-on for Active Directory (SA-LDAPSearch)

Release Notes for Splunk Supporting Add-on for Active Directory

This topic contains information on new features, known issues, and updates as we version the Splunk Supporting Add-on for Active Directory.

Version 3.0.8 of the Splunk Supporting Add-on for Active Directory was released on September 21, 2023.

What's new

The Splunk Supporting Add-on for Active Directory v3.0.8 fixed log injection vulnerabilities for ASCII Escape characters.

See the known issues and fixed issues of these release notes for other product updates.

Known issues

This version of the Splunk Supporting Add-on for Active Directory has the following reported known issues and workarounds. If no issues appear below, no issues have yet been reported.

Date filed Issue number Description
2023-10-18 TAG-14084 Splunk Cloud Customers using Distributed Search are not able to run the custom commands shipped with Splunk Supporting Add-on for Active Directory

Please raise a support ticket to perform the below steps:
  1. SSH to SH and navigate to Template:$SPLUNK HOME/etc/apps/SA-ldapsearch/local.
  2. Create a Template:Commands.conf file.
  3. Please add the below content to the Template:Commands.conf file.

{noformat}[ldapfilter] local = true

[ldapfetch] local = true

[ldapgroup] local = true{noformat}

  1. Please  restart the splunk after making the changes.

Fixed issues

This version of the Splunk Supporting Add-on for Active Directory fixes the following issues. If no issues appear below, no issues have yet been reported.

Last modified on 18 July, 2024
Data and source types for the Splunk Supporting Add-on for Active Directory   Workaround for default configuration stanza errors in distributed environments

This documentation applies to the following versions of Splunk® Supporting Add-on for Active Directory: 3.0.8

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters