All Apps and Add-ons

SA-ldapsearch lastLogon attr not returns value

louismai
Path Finder

Hi,

I ran a query:
| ldapsearch search="(&(objectClass=user)(!(objectClass=computer)))" attrs="sAMAccountName,distinguishedName,lastLogon,lastLogonTimestamp,division"

I found there are couple accounts witch lastLogon is null. But that field has value when I check that account in Active Directory. It is confusing because only some accounts have that issue.

Tks
Linh

0 Karma

spayneort
Contributor

The lastLogon attribute is not replicated between domain controllers. You may be getting a null value if the user has not logged on using the domain controller that ldapsearch is connecting to.

0 Karma

louismai
Path Finder

When I run a script in PowerShell on the same user, the PowerShell script returns a non-null value, while the app Active Directory still receives null value. It is very strange.

Tks
Louis

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...