All Apps and Add-ons

BUG: ldapfilter does not properly output whenCreated field.

peter_krammer
Communicator

App: SA-ldapsearch (Version 2.2.0)
There is a difference between the output of ldapsearch and ldapfilter when it comes to the whenCreated attribute.
In ldapfilter the output is not a date, but code that looks like it is supposed to format the date.
You can see it by running this query:

|ldapsearch domain=default search="(sAMAccountName=Administrator)" attrs="sAMAccountName,whenCreated"
|eval ldapsearch_whenCreated=whenCreated
|ldapfilter domain=default search="(sAMAccountName=$sAMAccountName$)" attrs="whenCreated"
|eval ldapfilter_whenCreated=whenCreated
|table sAMAccountName, ldapsearch_whenCreated, ldapfilter_whenCreated

alt text

0 Karma

marycordova
SplunkTrust
SplunkTrust

can you post screenshots of the output for both

@marycordova
0 Karma

BigCosta
Path Finder

The same problem with the whenChanged attribute

0 Karma

peter_krammer
Communicator

Yes of course.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...