Configuring an LDAP Directory Server Collector
Workload Security uses directory data to resolve identities in file-access activity. User Directory collectors do not provide a Test Connection function.
Configure the User Directory Collector before the ONTAP SVM Data Collector

| Select | Use it when |
|---|---|
Active Directory |
Users are stored in Active Directory and monitored activity is SMB; or Unix users are stored in Active Directory with uidNumber values and perform NFS activity. |
LDAP Directory Server |
Unix users are stored primarily in an LDAP directory and monitored activity is NFS. |
Both |
Identities are split across Active Directory and LDAP. Add one collector for each authoritative directory so all monitored identities can be resolved. |
| This page covers LDAP Directory Server Use this collector for Unix identities maintained in LDAP and used for NFS access. |
|---|
Before you begin
-
Sign in as a Data Infrastructure Insights Administrator or Account Owner.
-
Deploy and connect a Workload Security Agent that can reach the directory server.
-
Collect the LDAP Directory Server IP address or FQDN, Search Base, Bind DN, and Bind password.
-
Allow the Agent to reach the directory service. Typical ports are 389 for LDAP or StartTLS and 636 for LDAPS; use the port configured on your server.
-
Use a Bind DN account that can search the required directory scope and read every attribute mapped in the collector.
Add the LDAP Directory Server collector
1. Go to Workload Security > Collectors > User Directory Collectors and select + User Directory Collector.
2. Select LDAP Directory Server and select Continue.
3. Complete the connection fields and attribute mappings described below.
4. Review Advanced Configuration if service accounts use object classes that are not included in the default search.
5. Validate the configuration with ldapsearch or an LDAP browser, then select Save Collector.

LDAP Directory Server collector fields and default attribute mappings.
Connection fields
| Field | Requirement | What to enter |
|---|---|---|
Name* |
Mandatory |
A unique collector name. |
Agent |
Mandatory |
A connected Agent that can reach this LDAP server. |
Server IP/Domain Name* |
Mandatory |
The LDAP server IP address or FQDN. |
Search Base* |
Mandatory |
The base DN containing the users to import, such as cn=accounts,dc=example,dc=com. Use a narrower OU/CN DN only when the search should be limited to that subtree. |
Bind DN* |
Mandatory |
The full DN of an account permitted to search the base, such as uid=ws-reader,cn=users,cn=accounts,dc=example,dc=com. |
Bind Password* |
Mandatory |
The password for the Bind DN account. |
Protocol |
Defaulted |
LDAP, LDAPS, or LDAP with StartTLS. Select the protocol used by your server. |
Port* |
Mandatory |
The numeric directory port; commonly 389 or 636. |
Mandatory attribute mappings
Fields marked with an asterisk must have valid mappings. Keep the defaults unless your LDAP schema uses different attribute names.
| Workload Security field | Default LDAP attribute | Purpose |
|---|---|---|
Display Name* |
name |
Name displayed in Workload Security |
UNIXID* |
uidnumber |
Resolves numeric Unix user IDs in NFS activity |
User Name* |
uid |
Unix login or account name |
Optional attribute mappings
Select Include Optional Attributes only for profile data you want to import. Each mapping must match the actual LDAP schema, including case where the server treats it as significant.
| Profile value | Default LDAP attribute |
|---|---|
Email Address |
emailaddress |
Telephone Number |
telephonenumber |
Role |
title |
State |
st |
Country |
co |
Department |
departmentnumber |
Photo |
photo |
Manager DN |
manager |
Groups |
memberof |
Advanced Configuration: include the accounts you need
The Search Query controls which LDAP objects are imported. The default query includes common Unix and person object classes:
| (|(objectClass=posixAccount)(objectClass=person)(objectClass=nsperson)) |
|---|
Computer accounts, device accounts, application identities, or service accounts that use another objectClass remain unresolved. Inspect the object in an LDAP browser or with ldapsearch, then extend the query only for the required object types. For example:
| (objectClass=posixAccount) (objectClass=person) (objectClass=nsperson) (objectClass=device) (objectClass=applicationProcess) (objectClass=applicationEntity)) |
|---|
| Your LDAP schema is authoritative Object classes and attribute names vary by directory implementation. Confirm the object's actual schema and ensure the mandatory mappings have values before saving. Do not broaden the query more than necessary. |
|---|
Validate the configuration
| Test Connection is not available for User Directory collectors Validate network access, bind credentials, search scope, query results, and mapped attributes from a host with equivalent access before you save the collector. |
|---|
Use ldapsearch
Run a scoped search using the intended Bind DN. Replace the examples with your directory values and add the collector's Search Query as the LDAP filter.
| ldapsearch -o ldif-wrap=no -LLL -x -H ldap://ldap.example.com:389 -D "uid=ws-reader,cn=users,cn=accounts,dc=example,dc=com" -W -b "cn=accounts,dc=example,dc=com" '(|(objectClass=posixAccount)(objectClass=person)(objectClass=nsperson))' name uidNumber uid |
|---|
-
The bind succeeds with the exact account and password that the collector will use.
-
The search returns the expected human, computer, or service account.
-
Every mandatory mapped attribute exists and has a value on the returned object.
-
The Agent has the same DNS resolution and network path to the directory server.
After you save
-
The LDAP sync starts when the collector starts or restarts.
-
A directory with approximately 300,000 users can take about 15 minutes to sync.
-
User data refreshes automatically every 12 hours.
-
If the directory becomes unavailable, previously fetched user details remain, but new or changed users cannot be fetched until connectivity is restored.
-
User data is retained for 13 months without a refresh. User-directory data cannot be deleted independently of the tenant.
Troubleshooting
| Message or symptom | What to check |
|---|---|
Invalid credentials provided for the LDAP server. |
Verify the Bind DN and password. Also confirm that the account can search the configured Search Base. |
Failed to get the object corresponding to DN=… provided as search base. |
Correct the Search Base. Use the exact domain, DN, OU, or other supported scope. |
Failed to establish LDAP connection. |
Verify the LDAP server IP/FQDN, DNS resolution, protocol, port, and firewall path from the Agent. |
Failed to retrieve LDAP users…connection is null. |
Restart the collector. If it recurs, validate connectivity and the search with ldapsearch from an equivalent network location. |
Collector is RETRYING or reports AGENT008. |
Verify the server address and Search Base; then confirm the Agent can reach the directory service. |
A user or optional attribute is not displayed. |
Verify that the Search Query includes the object and that the mapped attribute name matches the directory schema, including case where applicable. Save to restart and resync. |
AcceptSecurityContext error, data 52e. |
Verify the credentials and Search Base. In Active Directory, data 52e indicates invalid credentials. |
ldap-port has type STRING rather than NUMBER. |
Enter a numeric port |