Skip to main content

IBM Directory Server for IBM (LDAP)

Download With Dependencies

IBM Directory Server for IBM (LDAP)

IBM Security Verify Directory LDAP

IBM® Security Verify Directory is a trusted identity infrastructure with LDAP, proxy, and virtual directory server capabilities. It includes management tools and GUIs for easy administration. As part of the IBM Verify portfolio, it supports identity management and is the default directory for WebSphere® and AIX®.

IBM Security Verify Directory LDAP

IBM® Security Verify Directory is a trusted identity infrastructure with LDAP, proxy, and virtual directory server capabilities. It includes management tools and GUIs for easy administration. As part of the IBM Verify portfolio, it supports identity management and is the default directory for WebSphere® and AIX®.

What does this pack do?

  • Modeling rules for audit events.
  • Parsing rules for IBM Security Verify Directory.
  • File collector configuration manual.

Filebeat Collection

To use the collector, use the following option to collect events from the vendor:

Configure the vendor and product for this specific collector.

XDRC (XDR Collector)

  1. Refer to the official XDR Collector documentation XDR Collectors.

  2. Replace [vendor]_[product]_raw with ibm_ldap_raw in your configuration.

When configuring the instance, you should use a YAML that configures the vendor and product, just as seen in the below configuration for the IBM Security Verify Directory product.

When configuring the instance, use a YAML file that specifies the vendor and product, as shown in the Filebeat Configuration File example below.

Filebeat Configuration file

- type: filestream
    enabled: true
    id: ldap
    paths: 
    - instance_home/idsslapd-instance_name/logs/audit.log
    processors: 
      - add_fields: 
          fields: 
            vendor: ibm
            product: ldap

This configuration collects data into a dataset named ibm_ldap_raw.

For more information on audit log file locations, see here

Note: The configuration uses the default location of the Message Tracking logs. If your Exchange server stores the logs in a different location, update the paths field in the YAML accordingly.

PUBLISHER

PLATFORMS

Cortex XSOARCortex XSIAM

INFO

CertificationRead more
Supported ByCortex
CreatedOctober 21, 2025
Last ReleaseOctober 21, 2025

DISCLAIMER
Content packs are licensed by the Publisher identified above and subject to the Publisher’s own licensing terms. Palo Alto Networks is not liable for and does not warrant or support any content pack produced by a third-party Publisher, whether or not such packs are designated as “Palo Alto Networks-certified” or otherwise.