Hi Meet,
As you can see from the error message, Elasticsearch is simply trying to follow referrals to ldap://ForestDnsZones.ad.test.com that AD returns in order to get all user information ( See more abour referrals in AD here )
You can instruct Elasticsearch to not follow these referrals ( especially given that athentication and information retrieval already works for you ) by setting
follow_referrals: false
in your realm configuration.