Slow performance with LDAP user.

103 views
Skip to first unread message

Facu Basgall

unread,
Aug 26, 2025, 2:59:56 PM (12 days ago) Aug 26
to Wazuh | Mailing List

Hello. I have integrated Wazuh with LDAP, but I notice that when I log in with a valid AD user, Wazuh responds much (much!) slower and takes much longer to process web requests.

With the default “admin” user, it works normally.

Juan Felipe González Ortiz

unread,
Aug 26, 2025, 4:40:06 PM (12 days ago) Aug 26
to Wazuh | Mailing List
Hi Facu, I'll look into it and let you know what I find out.

Juan Felipe González Ortiz

unread,
Aug 28, 2025, 11:21:16 AM (10 days ago) Aug 28
to Wazuh | Mailing List

Hi Facu,

Thanks for reaching out and reporting this behavior. It’s possible that the indexer is attempting to check other authentication backends before validating against LDAP, which can cause the login to feel much slower.

To better understand your setup, could you please share the following files (feel free to redact any sensitive information):

  • /etc/wazuh-indexer/opensearch-security/config.yml

  • /etc/wazuh-indexer/opensearch-security/roles_mapping.yml

Facu Basgall

unread,
Aug 28, 2025, 2:02:13 PM (10 days ago) Aug 28
to Wazuh | Mailing List

Hi, I am sharing the requested files with you.

ldap_roles_mapping.yml
ldap_config.yml

Juan Felipe González Ortiz

unread,
Sep 1, 2025, 11:29:33 AM (6 days ago) Sep 1
to Wazuh | Mailing List

Here’s the English version of the response:


Hi Facu,

We’ve reviewed your case and, at first glance, your configuration looks correct. To move forward, our team will simulate an LDAP environment and test some scenarios.

In the meantime, could you share how many groups and users you currently have in your directory? This detail is important since the number of objects can directly affect the LDAP performance with Wazuh.

Facu Basgall

unread,
Sep 1, 2025, 11:45:58 AM (6 days ago) Sep 1
to Wazuh | Mailing List

Hi! How many groups and users in the AD in general or in the Wazuh Admin and Wazuh Readers groups?

Juan Felipe González Ortiz

unread,
Sep 2, 2025, 11:12:13 AM (5 days ago) Sep 2
to Wazuh | Mailing List
Hi, In the Wazuh groups, but also if it's possible the total amount of groups.

This is to be able to replicate an environment as similar to yours as possible.

Facu Basgall

unread,
Sep 3, 2025, 10:38:58 AM (4 days ago) Sep 3
to Wazuh | Mailing List

Good.

I have in my AD approximately 4900 users, 9200 groups

But in the Wazuh Admin group I have only 7 users and in the Wazuh Readers group only 3 users.

Juan Felipe González Ortiz

unread,
Sep 4, 2025, 9:02:39 AM (3 days ago) Sep 4
to Wazuh | Mailing List

Hi, most likely the poor performance is due to the users and groups issue. 

I'm going to set up an environment simulating that number of groups and users and let you know.

Reply all
Reply to author
Forward
0 new messages