All Apps and Add-ons

SA-ldapsearch lastLogon attr not returns value

louismai
Path Finder

Hi,

I ran a query:
| ldapsearch search="(&(objectClass=user)(!(objectClass=computer)))" attrs="sAMAccountName,distinguishedName,lastLogon,lastLogonTimestamp,division"

I found there are couple accounts witch lastLogon is null. But that field has value when I check that account in Active Directory. It is confusing because only some accounts have that issue.

Tks
Linh

0 Karma

spayneort
Contributor

The lastLogon attribute is not replicated between domain controllers. You may be getting a null value if the user has not logged on using the domain controller that ldapsearch is connecting to.

0 Karma

louismai
Path Finder

When I run a script in PowerShell on the same user, the PowerShell script returns a non-null value, while the app Active Directory still receives null value. It is very strange.

Tks
Louis

0 Karma
Get Updates on the Splunk Community!

Splunk App for Anomaly Detection End of Life Announcement

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...