Has Anyone Got this working I get "Received malformed data (ER1010)" with all the example given???
forgot to mention tried the username@domain.com what worked for me was domain\username
and I now get
ERROR
invalid attribute description
now to find out why.... Anyone know what the attribute description that can be used in the SIEM?
We have got this working with a simple LDAP query. You need to setup a dynamic watchlist and then enter the relevant LDAP query into the query field.
Alternatively, I also have another watchlist which I populate differently. I make the LDAP query from a Linux server, then enrich the data on that Linux box. Finally, the Linux box makes an API call to ESM to populate the watchlist. This happens nightly so the watchlist is always current.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA