Announcing the Saviynt Knowledge Exchange unifying the Saviynt forums, documentation, training,
and more in a single search tool across platforms. Read the announcement here.

memberuid account to entitlement mapping

TAR
New Contributor
New Contributor

We have a linux ldap connection where the group membership is stored in group object as multivalued attribute (attribute name in memberuid), when we ran access import, groups are getting created in saviynt but mapping of accounts to entitlements are not happening. Any insights on this. Below are the jsons:

Account mapping:

[CUSTOMPROPERTY19::nsUniqueId#String,
CUSTOMPROPERTY18::entrydn#String,
CUSTOMPROPERTY20::nameinnamespace#String,
CUSTOMPROPERTY1::entrydn#String,
ACCOUNTID::uid#String,
NAME::uid#String,
CREATED_ON::createTimestamp#customDate--yyyyMMddHHmmss,
UPDATEDATE::modifyTimestamp#customDate--yyyyMMddHHmmss,
ACCOUNTCLASS::objectClass#String,
CREATOR::creatorsName#String,
CUSTOMPROPERTY2::cn#String,
CUSTOMPROPERTY3::uidNumber#String,
CUSTOMPROPERTY4::gidNumber#String,
CUSTOMPROPERTY5::modifiersName#String,
CUSTOMPROPERTY6::entryid#String,
CUSTOMPROPERTY7::nsUniqueId#String,
CUSTOMPROPERTY8::parentid#String,
CUSTOMPROPERTY9::homeDirectory#String,
CUSTOMPROPERTY10::loginShell#String,
CUSTOMPROPERTY51::host#String,
CUSTOMPROPERTY12::nsAccountLock#String,
CUSTOMPROPERTY13::shadowMax#String,
CUSTOMPROPERTY14::shadowWarning#String,
CUSTOMPROPERTY15::lastLoginTime#customDate--yyyyMMddHHmmss,
CUSTOMPROPERTY16::passwordExpirationTime#customDate--yyyyMMddHHmmss,
CUSTOMPROPERTY17::pwdReset#String,
RECONCILATION_FIELD::ACCOUNTID
]

 

groupImportMapping

 

{
"importGroupHierarchy": "false",
"entitlementTypeName": "memberUid",
"performGroupAccountLinking": "true",
"groupObjectClass": "(objectClass=posixGroup)",
"mapping": "memberHash:memberUid_char,entitlement_value:nameinnamespace_char,entitlement_glossary:description_char,lastscandate:createtimestamp_date,displayName:cn_char,customProperty1:entryid_char,customProperty2:objectclass_char,customProperty3:gidnumber_char,customProperty7:creatorsname_char,customProperty4:memberuid_char,customProperty5:modifiersname_char,customProperty6:uidNumber_char,customProperty5:entrydn_char,RECONCILATION_FIELD:customproperty18,customproperty18:nsUniqueId_char"
}

 

TAR_0-1714745942016.png

 

11 REPLIES 11

NM
Regular Contributor III
Regular Contributor III

Hi @TAR , could you share other details from connection? Mask the sensitive values.

TAR
New Contributor
New Contributor

Hi @NM 

Please check the below screenshot:

 

TAR_0-1714748994903.pngTAR_1-1714749055942.pngTAR_2-1714749080920.pngTAR_3-1714749110956.pngTAR_4-1714749139891.pngTAR_5-1714749169542.pngTAR_6-1714749190178.png

 

NM
Regular Contributor III
Regular Contributor III

Hi @TAR config looks okay, do you see any mapping after running account and access import seperately?

TAR
New Contributor
New Contributor

Hi @NM 

What kind of mapping are you referring to here, when access import is ran, I see the below logs:

 

2024-05-03T14:11:05.590625213Z stdout F 2024-05-03 14:11:05,590 [quartzScheduler_Worker-10] DEBUG services.AdImportService - [jwwegert] is not available
 
2024-05-03T09:11:06-05:00-ecm-worker--null-q56ls--2024-05-03T14:11:05.590659468Z stdout F 2024-05-03 14:11:05,590 [quartzScheduler_Worker-10] DEBUG services.AdImportService - [cmfranco] is not available
 
2024-05-03T09:11:06-05:00-ecm-worker--null-q56ls--2024-05-03T14:11:05.590698396Z stdout F 2024-05-03 14:11:05,590 [quartzScheduler_Worker-10] DEBUG services.AdImportService - [mfma] is not available
 
2024-05-03T09:11:06-05:00-ecm-worker--null-q56ls--2024-05-03T14:11:05.590751943Z stdout F 2024-05-03 14:11:05,590 [quartzScheduler_Worker-10] DEBUG services.AdImportService - [sxtrupia] is not available
 
2024-05-03T09:11:06-05:00-ecm-worker--null-q56ls--2024-05-03T14:11:05.590781362Z stdout F 2024-05-03 14:11:05,590 [quartzScheduler_Worker-10] DEBUG services.AdImportService - [jwwegert] is not available
 
2024-05-03T09:11:06-05:00-ecm-worker--null-q56ls--2024-05-03T14:11:05.590814814Z stdout F 2024-05-03 14:11:05,590 [quartzScheduler_Worker-10] DEBUG services.AdImportService - [MFMA] is not available
 
2024-05-03T09:11:06-05:00-ecm-worker--null-q56ls--2024-05-03T14:11:05.590852645Z stdout F 2024-05-03 14:11:05,590 [quartzScheduler_Worker-10] DEBUG services.AdImportService - [sxtrupia] is not available
 
2024-05-03T09:11:06-05:00-ecm-worker--null-q56ls--2024-05-03T14:11:05.590877667Z stdout F 2024-05-03 14:11:05,590 [quartzScheduler_Worker-10] DEBUG services.AdImportService - [kmcoles] is not available
 
2024-05-03T09:11:06-05:00-ecm-worker--null-q56ls--2024-05-03T14:11:05.590913131Z stdout F 2024-05-03 14:11:05,590 [quartzScheduler_Worker-10] DEBUG services.AdImportService - [bhdowns] is not available
 
2024-05-03T09:11:06-05:00-ecm-worker--null-q56ls--2024-05-03T14:11:05.590965889Z stdout F 2024-05-03 14:11:05,590 [quartzScheduler_Worker-10] DEBUG services.AdImportService - [tqtran] is not available
 
2024-05-03T09:11:06-05:00-ecm-worker--null-q56ls--2024-05-03T14:11:05.590998189Z stdout F 2024-05-03 14:11:05,590 [quartzScheduler_Worker-10] DEBUG services.AdImportService - [mastefan] is not available
 
2024-05-03T09:11:06-05:00-ecm-worker--null-q56ls--2024-05-03T14:11:05.59103107Z stdout F 2024-05-03 14:11:05,591 [quartzScheduler_Worker-10] DEBUG services.AdImportService - [jwwegert] is not available
 
2024-05-03T09:11:06-05:00-ecm-worker--null-q56ls--2024-05-03T14:11:05.59106785Z stdout F 2024-05-03 14:11:05,591 [quartzScheduler_Worker-10] DEBUG services.AdImportService - [mfma] is not available
 
2024-05-03T09:11:06-05:00-ecm-worker--null-q56ls--2024-05-03T14:11:05.591108892Z stdout F 2024-05-03 14:11:05,591 [quartzScheduler_Worker-10] DEBUG services.AdImportService - [mfma] is not available
 
2024-05-03T09:11:06-05:00-ecm-worker--null-q56ls--2024-05-03T14:11:05.59115277Z stdout F 2024-05-03 14:11:05,591 [quartzScheduler_Worker-10] DEBUG services.AdImportService - [sapadm is not available
 
2024-05-03T09:11:06-05:00-ecm-worker--null-q56ls--2024-05-03T14:11:05.591154705Z stdout F 2024-05-03 14:11:05,591 [quartzScheduler_Worker-10] DEBUG services.AdImportService - aetadm is not available
 
2024-05-03T09:11:06-05:00-ecm-worker--null-q56ls--2024-05-03T14:11:05.59117721Z stdout F 2024-05-03 14:11:05,591 [quartzScheduler_Worker-10] DEBUG services.AdImportService - apdougla is not available
 
2024-05-03T09:11:06-05:00-ecm-worker--null-q56ls--2024-05-03T14:11:05.591181358Z stdout F 2024-05-03 14:11:05,591 [quartzScheduler_Worker-10] DEBUG services.AdImportService - aksulliv is not available
 
2024-05-03T09:11:06-05:00-ecm-worker--null-q56ls--2024-05-03T14:11:05.59119422Z stdout F 2024-05-03 14:11:05,591 [quartzScheduler_Worker-10] DEBUG services.AdImportService - jwjoiner is not available
 
2024-05-03T09:11:06-05:00-ecm-worker--null-q56ls--2024-05-03T14:11:05.591209978Z stdout F 2024-05-03 14:11:05,591 [quartzScheduler_Worker-10] DEBUG services.AdImportService - root is not available
 
2024-05-03T09:11:06-05:00-ecm-worker--null-q56ls--2024-05-03T14:11:05.59122841Z stdout F 2024-05-03 14:11:05,591 [quartzScheduler_Worker-10] DEBUG services.AdImportService - tcmoeur is not available
 
2024-05-03T09:11:06-05:00-ecm-worker--null-q56ls--2024-05-03T14:11:05.591244636Z stdout F 2024-05-03 14:11:05,591 [quartzScheduler_Worker-10] DEBUG services.AdImportService - vkmallel] is not available
 
2024-05-03T09:11:06-05:00-ecm-worker--null-q56ls--2024-05-03T14:11:05.591279484Z stdout F 2024-05-03 14:11:05,591 [quartzScheduler_Worker-10] DEBUG services.AdImportService - [chhogan] is not available
 
2024-05-03T09:11:06-05:00-ecm-worker--null-q56ls--2024-05-03T14:11:05.592181661Z stdout F 2024-05-03 14:11:05,592 [quartzScheduler_Worker-10] DEBUG services.AdImportService - Start delete Account_entitlements1 and Entitlements2 not imported in this job for entitlementIds: 249

NM
Regular Contributor III
Regular Contributor III

Hi @TAR, trigger account import first and share the logs plus check once if you see any entitlement mapping for account ... Then trigger access import, share logs and check entitlement mapping if it is affected.

Below attribute is missing in mapping json

"groupAccountMappingAttributeName":"member", 

Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.

Hi @rushikeshvartak 

adding that attribute also did not work

Please share logs in text file


Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.

Hi @rushikeshvartak 

 

Please find attached

NM
Regular Contributor III
Regular Contributor III

Hi @TAR , were you able to resolve the issue?

TAR
New Contributor
New Contributor

Hi @NM 

I have ran both recon but the mapping is still not happening.

attached is the logs