All Apps and Add-ons

SA-ldapsearch lastLogon attr not returns value

louismai
Path Finder

Hi,

I ran a query:
| ldapsearch search="(&(objectClass=user)(!(objectClass=computer)))" attrs="sAMAccountName,distinguishedName,lastLogon,lastLogonTimestamp,division"

I found there are couple accounts witch lastLogon is null. But that field has value when I check that account in Active Directory. It is confusing because only some accounts have that issue.

Tks
Linh

0 Karma

spayneort
Contributor

The lastLogon attribute is not replicated between domain controllers. You may be getting a null value if the user has not logged on using the domain controller that ldapsearch is connecting to.

0 Karma

louismai
Path Finder

When I run a script in PowerShell on the same user, the PowerShell script returns a non-null value, while the app Active Directory still receives null value. It is very strange.

Tks
Louis

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...