[Date Prev][Date Next]
[Chronological]
[Thread]
[Top]
Re: accesslog search filter using reqAttr
- To: openldap-technical@openldap.org
- Subject: Re: accesslog search filter using reqAttr
- From: "John Alex." <alexoz66@gmail.com>
- Date: Mon, 08 Sep 2014 16:45:19 +0300
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type:content-transfer-encoding; bh=fSpdAaDQt3QJMim2UsyWDd3EEMNAJFNFHAkE1TjtIMI=; b=oqFl7WEacQqQIFmkkXwkL4fRudSHE4GiUgecC586NHJN+O4Lb/LZ4pvkbGa0T24a1G XB5N9MeiLdgzX0bY6y4cii64Ga/WmNBxnAifd0AlH9jGt0BKEBkxeagk6PThpnOAnUr8 Eh7R2TNN0gLxWR+/QUVFn0YSJQR34RvhJEYq8rJota7W2CR+uPbLTp2oKymksRzVUEDY TQHusRkOyEyEwV/4sXrzWVuWIV3kcjX1n4i9PW+/utFU2gWsC4NOlQPlP4tLZ5u7qvNN otO/m6DG1DqFT6WvJ0+ZnfT5BoxPA7ijEJKI+inBIkPghxy7SFFs40GKl5GiYQHon0RO LlgQ==
- In-reply-to: <540594B4.6060103@gmail.com>
- References: <540594B4.6060103@gmail.com>
- User-agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.0
This appears to be a bug, filed an ITS (#7934)
On 09/02/2014 12:58 PM, John Alex. wrote:
> Hi all,
>
> Is anyone using "reqAttr" of accesslog overlay to find ldap requests for specific attributes?
>
> Our accesslog db contains some entries like for example:
>
> dn: reqStart=20140902092840.000001Z,cn=accesslog
> objectClass: auditSearch
> reqStart: 20140902092840.000001Z
> reqEnd: 20140902092840.000002Z
> reqType: search
> reqSession: 1018
> reqAuthzID: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth
> reqDN: dc=example,dc=com
> reqResult: 0
> reqScope: sub
> reqDerefAliases: never
> reqAttrsOnly: FALSE
> reqFilter: (objectClass=*)
> reqAttr: userPassword
> reqEntries: 7
> reqTimeLimit: 3600
> reqSizeLimit: 500
>
> I am trying to search using the filter "(reqAttr=userPassword)" but no results are
> returned, while "(reqAttr=*)" returns all entries. What am I missing?
>
> Using version 2.4.39
>
> John
>